Yes, I was hacked. Hard.
So maybe you saw my Twitter going nuts tonight. Or you saw Gizmodo's Twitter account blow up. Or you saw this in AllThingsD. Or this in the DailyDot. Although embarrassing, Twitter was the least of it. In short, someone gained entry to my iCloud account …
Context & Ripple Effects
A Gizmodo writer lost control of his digital life in a single evening: the attacker got into his iCloud account first, and from there his Twitter — including the shared Gizmodo account — started posting unauthorized content. He says Twitter was 'the least of it,' which is the telling part: the breach ran through the cloud account, not the social network.
The episode rhymes with an older pattern in this corpus — the 2009 Twitter hack that began with a weak password showed how one compromised credential cascades across a platform. What is new in 2012 is where the cascade starts: not at a single service, but at the account-recovery layer of a consumer cloud, which then unlocks everything attached to it.
First-order effects
- The writer and Gizmodo are dealing with live damage right now: unauthorized posts on both his personal and the publication's Twitter accounts, and an intruder inside his iCloud account with access to whatever it syncs.
- Every service tied to that iCloud identity — mail, photos, linked logins — is exposed until the recovery chain is cut, making containment the immediate task rather than cleanup.
Second-order effects
- Apple faces pointed questions about how its account-support and recovery process let someone take over an iCloud account, because the attack path was the human recovery layer, not a password crack.
- Other consumer cloud providers get pulled into the same scrutiny: if iCloud-to-Twitter is the demonstrated kill chain, every platform that offers 'verify by another account' recovery inherits the same weakness.
Third-order effects
- If single-account compromise keeps unlocking whole digital lives, the industry's structural answer points toward layered authentication — two-factor verification and hardened recovery procedures — replacing the password-plus-support-call model that made this attack possible.
- Publications and individuals who run high-profile accounts become the test cases that force cloud vendors to treat account recovery as a security surface in its own right, not customer-service overhead.
The trend: Consumer cloud accounts are becoming the single point of failure for a person's entire online identity, pushing the industry from passwords toward hardened, multi-layered account recovery.