Newsdeck

Newsdeck

Twitter silences some verified accounts after wave of hacks

(Photo: Unsplash/Sara Kurfess)

SAN FRANCISCO, July 15 (Reuters) - Multiple high-profile Twitter accounts were hijacked on Wednesday, with some of the platform's top voices - including U.S. presidential candidate Joe Biden, reality TV star Kim Kardashian, former U.S. President Barack Obama and billionaire Elon Musk, among many others - used to solicit digital currency.

By Joseph Menn, Raphael Satter and Katie Paul

 

Hours after the first wave of hacks, the cause of the breach had not yet been made public. In a sign of the seriousness of the problem, Twitter took the extraordinary step of preventing at least some verified accounts from publishing messages altogether.

It was not clear whether all verified users were affected but, if they were, it would have a huge impact on the platform and its users. Verified users include celebrities, journalists, and news agencies as well as governments, politicians, heads of state and emergency services.

Most of those users had their ability to tweet restored hours later, Twitter said in a statement, although it cautioned account functionality “may come and go” as it continued to work on a solution.

Chief Executive Jack Dorsey said the company was diagnosing the problem and pledged to share “everything we can when we have a more complete understanding of exactly what happened.”

“Tough day for us at Twitter. We all feel terrible this happened,” he said in a tweet.

The unusual scope of the problem suggests hackers may have gained access at the system level, rather than through individual accounts. While account compromises are not rare, experts were surprised at the sheer scale and coordination of Wednesday’s incident.

“This appears to be the worst hack of a major social media platform yet,” said Dmitri Alperovitch, who co-founded cybersecurity company CrowdStrike.

Congressman Frank Pallone, the chairman of the House energy and commerce committee, called on the company to account for what went wrong.

“Twitter needs to explain how all of these prominent accounts were hacked,” he said in a tweet.

SECURITY BREACH

Some experts said it seemed probable that hackers had access to Twitter’s internal infrastructure.

“It is highly likely that the attackers were able to hack into the back end or service layer of the Twitter application,” said Michael Borohovski, director of software engineering at security company Synopsys.

“If the hackers do have access to the backend of Twitter, or direct database access, there is nothing potentially stopping them from pilfering data in addition to using this tweet-scam as a distraction,” he said.

Twitter told Reuters just before 5 p.m. EDT that it was investigating what it later called a “security incident” and would be issuing a statement shortly. However, as of 9 p.m. the company still had not issued an explanation.

Shares in the social media company tumbled almost 5% in trading after the market close before paring their losses.

Earlier, some of the platform’s biggest users appeared to be struggling to re-establish control of their accounts. In the case of billionaire Tesla Chief Executive Elon Musk, for example, one tweet soliciting cryptocurrency was removed and, sometime later, another one appeared, and then a third.

Among the others affected: rapper Kanye West, Amazon founder Jeff Bezos, investor Warren Buffett, Microsoft co-founder Bill Gates, and the corporate accounts for Uber and Apple. Several accounts of cryptocurrency-focused organizations were also hijacked.

Altogether, the affected accounts had tens of millions of users.

Biden’s campaign was “in touch” with Twitter, according to a person familiar with the matter. The person said the company had locked down the Democrat’s account “immediately following the breach and removed the related tweet.” Tesla and other affected companies were not immediately available for comment.

Publicly available blockchain records show the apparent scammers received more than $100,000 worth of cryptocurrency.

Several experts said the incident raised questions about Twitter’s cybersecurity.

“It’s clear the company is not doing enough to protect itself,” said Oren Falkowitz, former CEO of Area 1 Security.

Alperovitch, who now chairs the Silverado Policy Accelerator, said that, in a way, the public had dodged a bullet so far.

“We are lucky that given the power of sending out tweets from the accounts of many famous people, the only thing that the hackers have done is scammed about $110,000 in bitcoins from about 300 people,” he said. (Reporting by Joseph Menn, Raphael Satter, and Katie Paul; Additional reporting by Elizabeth Culliford in San Francisco; Christopher Bing, David Shepardson and Chris Sanders in Washington; and Trevor Hunnicutt in New York. Editing by Sandra Maler, Diane Craft, Aurora Ellis and Lincoln Feast.)

Gallery

Please peer review 3 community comments before your comment can be posted

We would like our readers to start paying for Daily Maverick...

…but we are not going to force you to. Over 10 million users come to us each month for the news. We have not put it behind a paywall because the truth should not be a luxury.

Instead we ask our readers who can afford to contribute, even a small amount each month, to do so.

If you appreciate it and want to see us keep going then please consider contributing whatever you can.

Support Daily Maverick→
Payment options

Premier Debate: Gauten Edition Banner

Join the Gauteng Premier Debate.

On 9 May 2024, The Forum in Bryanston will transform into a battleground for visions, solutions and, dare we say, some spicy debates as we launch the inaugural Daily Maverick Debates series.

We’re talking about the top premier candidates from Gauteng debating as they battle it out for your attention and, ultimately, your vote.

Daily Maverick Elections Toolbox

Feeling powerless in politics?

Equip yourself with the tools you need for an informed decision this election. Get the Elections Toolbox with shareable party manifesto guide.