Twitter Hack Only Took 24 Hours from Start to Takeover



Twitter Hack A report from the New York Department of Financial Services covering the high-profile Twitter account hack from earlier in the year reveals how little time an attack takes to be successful.

I wrote recently about a large number of high-profile twitter accounts being hacked all to promote a fake bitcoin doubling scam. Accounts that were hacked included Apple, Elon Musk and Joe Biden.

A new report on the attack from the New York State Department of Financial Services provides startling details on who carried out the attack and how little effort it really took. According to the report, the three perpetrators were two teenagers from the U.S. and a 22-year old from the U.K. The scam began with vishing Twitter employees by pretending to be members of Twitter’s internal IT calling about an issue with VPN access. Once they gained control over credentials that would provide them an ability to take over Twitter accounts, they took over several high-profile accounts and began tweeting the so-called CryptoForHealth scam.

From start to finish, it only took these youngsters less than one day to use basic social engineering tactics to compromise one of the largest social media giants on the planet. It goes to show you that even organizations with evident efforts to ensure the highest levels of cybersecurity can be taken down by a single employee.

It’s why I talk about the importance of Security Awareness Training so much; it only takes one careless employee, one click, one answering of the phone, etc. to turn an organization into a victim. By educating them about the importance of paying attention to the ever-present threat of cybercriminal activity, your users build up their vigilance and are less likely to fall for scams – even one as simple as this one.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/phishing-security-test-offer



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews