Jack Dorsey's Twitter account was hacked on Friday, possibly by a group that calls themselves the Chuckle Squad, which posted a number of racist tweets
and he's the CEO of Twitter John Callaham / Android Authority : Regularly changing your Twitter password is important, as Twitter CEO found out Tweets: @twittercomms : We're aware that @jack was compromised and investigating what happened. @twittercomms : @jack The phone number associated with the account was compromised due to a security oversight by the mobile provider. This allowed an unauthorized person to compose and send tweets via text message from the phone number. That issue is now resolved. Alex Stamos / @alexstamos : So they get control of the phone number of a billionaire (who is also the CEO of a massive payment processor) and they use it to send racist tweets? This is like pulling off a heist of a McLaren F1, taking it for a joyride and crashing into the median in three minutes. https://twitter.com/... James O'Malley / @psythor : .@jack's hacked tweets are being posted from an app called Cloudhopper, which is apparently an app Twitter acquired previously that had something to do with SMS. So his account appears not breached - but rather Jack's account is still hooked up to an old service that got hacked. pic.twitter.com/V3U5rJXrDP @twittercomms : @jack The account is now secure, and there is no indication that Twitter's systems have been compromised. Ryan Mac / @rmac18 : Twitter statement on @jack: “The phone number associated with the account was compromised due to a security oversight by the mobile provider. This allowed an unauthorized person to compose and send tweets via text message from the phone number. That issue is now resolved.” @dailymonitor : Twitter CEO Jack Dorsey's Twitter account was hacked on Friday afternoon by a group that calls itself the Chuckle Squad. The profile, which has more than four million followers, tweeted highly offensive messages against black people for about 15 minutes #MonitorUpdates https://twitter.com/... Brett Shavers / @brett_shavers : Not that I would ever hack @jack's account, but if I were...I would have tweeted “The #Twitter edit button is coming.” https://www.theverge.com/... https://twitter.com/... Kevin Fox / @kfury : One might suggest that the right answer isn't to figure out how to convince Twitter's CEO to carry a secure laptop for tweeting, but rather engineer a system that can have that level of security when tweeting from the phones their customers use. https://twitter.com/... Tim O'Brien / @timobrien : Dorsey, hacked twice, “has shunned efforts to better secure him and his devices [and] prefers to do the majority of his work from his iPhone...Part of the reason...was that Twitter's CEO did not like to carry items with him during his long walks.” https://www.buzzfeednews.com/ ... Daniel Nazer / @danielnazer : Twitter's promise vs. Twitter's reality. https://twitter.com/... Ben Dreyfuss / @bendreyfuss : Jack on prozac, says flak, after hack from SIM crack make jack sad sack but jack bounce back after sipping cognac on horseback amid lilac and making wisecrack with another megalomaniac http://www.wired.com/... Bunny Sparber / @maxsparber : Is it more believable that Jack is a racist and accidentally tweeted racist stuff or that he is so incompetent that he got hacked on his own platform. I literally can't decide. Sarah Frier / @sarahfrier : @jack @realDonaldTrump What if the president was hacked? “Shouldn't be too bad,” @realDonaldTrump says. https://www.bloomberg.com/... (It would probably be bad.) https://twitter.com/... Tom Warren / @tomwarren : AT&T fucked up again and let someone SIM swap Twitter CEO's number. Carriers don't do enough to protect against this. https://twitter.com/... Ryan Mac / @rmac18 : @jack A source familiar now confirms: @jack had his sim swapped. There it is. That's the tweet. Mat Honan / @mat : We got confirmation Dorsey was SIM jacked. Amazing the carriers haven't set up better protections against this https://www.buzzfeed.com/... Richard Lawler / @rjcc : Unfortunately, 2FA or checking your connected apps won't protect you from whoever hijacked @Jack. It looks like he was the victim of the increasingly common (and potentially devastating) SIM-swap, then the attackers just texted 40404 from his number. https://www.engadget.com/... https://twitter.com/... Dave Lee / @daveleebbc : Twitter tells BBC it is urgently investigating what has happened to @jack's account, would not say why the account hasn't been suspended or deactivated yet as still looking into it. Looks like tweets have stopped, many of the offending tweets seem to be disappearing now. Jake Williams / @malwarejake : Twitter founder @jack had his account hacked. I'm not laughing at all, but if there's any justice in this world, he'll have to engage with @TwitterSupport like a normal victim and get a chance to see first hand how horrible the experience is. Hopefully this leads to some change. pic.twitter.com/9YPwzXuyNS Dan Kaminsky / @dakami : Not everyone wants to be a drug dealer. Not everyone wants to rob a billionaire. Some people just want to watch the world point and laugh. https://twitter.com/... Josh Raby / @joshraby : why would you hack someone's account just to tweet the things they already think https://twitter.com/... James Todaro / @jamestodaromd : Jack Dorsey got SIM swapped today giving the hacker access to his twitter account. If the CEO of twitter can get SIM swapped, you better believe that it can happen to you. If you use your real name on social media (eg Crypto Twitter), do NOT use SMS text as your 2FA. https://twitter.com/... Whitney Merrill / @wbm312 : Ha knew it. It's always sim jacking. Our mobile service providers are the weakest link. https://twitter.com/... Mo Elleithee / @moelleithee : If the Twitter CEO's account can be hacked, so can the unsecured account of the President of the United States. Just saying. https://www.axios.com/... Zack Whittaker / @zackwhittaker : Welp. Reads like @jack got SIM swapped. https://twitter.com/... Ryan Mac / @rmac18 : Spoke with a former Twitter employee who said Dorsey's hack should be embarrassing for the CEO. That person says Dorsey, who is known to work only on his iPhone, was told to use a more secure laptop in the past but refused. Twitter declined to comment. https://www.buzzfeednews.com/ ... Kim Zetter / @kimzetter : Let's hope that this becomes the SIM-jacking case that sufficiently shames the mobile carriers into finally doing something about this security problem. https://twitter.com/... Ryan Mac / @rmac18 : @jack Our updated story has this: -Twitter won't confirm if @jack had his SIM card hijacked -Twitter declined to comment on if hackers had access to DMs -New comments from former employees who talked about lax account security for execs https://www.buzzfeednews.com/ ... Nic Nguyen / @itsnicolenguyen : EVEN JACK was sim-hijacked. Put a pin # on your mobile accounts y'all https://twitter.com/... Tom Gara / @tomgara : I feel bad for Jack Dorsey but this is what happens when your entire staff goes to Burning Man Ben Collins / @oneunderscore__ : Some reporting from me from within the Discord of Jack's hackers. —Hackers tried to rifle through Jack's private messages, but open DMs made it too hard to tell what was important —Users in the chat had spelled out “DONALD TRUMP” in reaction emojis https://www.nbcnews.com/... Ryan Mac / @rmac18 : Among the apparent reasons Dorsey refused the laptop: He didn't like carrying things on his long walks. Benedict Evans / @benedictevans : It's 2019 and Twitter still obliges you to use SMS 2FA. Come on. 🤦🏻♂ ️ Ben Collins / @oneunderscore__ : After a horrifying 20 minutes of n-words and actual Nazi propaganda being pushed from the CEO's hacked account, maybe Twitter will take the gamification of harassment and racism as seriously as its victims have been for years. Bryan Haggerty / @bhaggs : Cloudhopper was the name of the company we acquired eons ago to help bolster our SMS service. Apparently we still use the name as the client ID. Rob Rousseau / @robrousseau : lol I was so busy toiling in the content mines today that I missed @jack's account getting stolen by the very people he refuses to remove from this cursed website https://twitter.com/... Tom Warren / @tomwarren : SIM swapping Jack is probably the most likely scenario. It's surprisingly easy to get carriers to give up your SIM with just a few account details. Also very hard to protect against Joseph Cox / @josephfcox : Yes, @jack apparently had 2FA on his account. At least judging by answers he gave here https://www.intelligence.senate.gov/ ... pic.twitter.com/Zaz6mZUzKf Anil Dash / @anildash : Important context, because it means a linked app was compromised, but they likely had no access to DMs, no copy of his password, and Twitter itself (including, presumably, 2-factor authentication) wasn't the vulnerability. https://twitter.com/... @verge : After @jack's hack, it might be a good time to protect your Twitter account against application hijacks. Here's how: https://www.theverge.com/... Jeremy Ross / @jebus911 : Smart enough to hack Jack's account, not smart enough to use it to pump a shitcoin. @thefurlinator : feral hogs, bedbug stephens, jack being hacked. august 2019 is the easily the greatest month in twitter history. we may never get as pure a time as this ever again https://twitter.com/... Kristin Chirico / @lolacoaster : i did my own investigation and what happened is that there are nazis on the platform https://twitter.com/... Tom Warren / @tomwarren : Cloudhopper is used by Twitter to let you tweet via SMS. It's likely the culprits either spoofed an SMS or gained access to something at Cloudhopper's end. Either way, I'd doubt they had full access to his account. We'll likely never know exactly what happened, though Ryan Mac / @rmac18 : I'm having flashbacks to the day that Twitter contractor nuked Trump's account Tom Warren / @tomwarren : Everyone will say “make sure you use a secure password and enable 2FA” on Twitter but neither of those things matter if you auth third-party apps to your account. The source of the bad tweets was via cloud hopper, which jack has used before. Check your apps people 👋 https://twitter.com/... Lard Shmoopy / @zabbadab : Considering he still alows Trump to have an account it's clear he was compromised long ago Graham Cluley / @gcluley : Four years ago Twitter's CFO has his account breached. He wasn't using 2FA. https://www.grahamcluley.com/ ... I find it hard to think Twitter's security team would let @jack make the same mistake. My hunch would be third party app compromised, but we will see. Pierre-Olivier Carles / @pocarles : It's a shame he doesn't know anyone at Twitter to fix it, and get his account back. I would try Burning Man to reach someone if I was him. Half of Twitter must be there as we talk... https://twitter.com/... Elizabeth Joh / @elizabeth_joh : Watching the hacked account of this website's CEO and feeling not too keen about the POTUS tweeting about important Article II type stuff here Alex Howard / @digiphile : Fast-twitch reporting by @BuzzFeed on the @jack hack https://www.buzzfeednews.com/ ... Looks like they amplified a Discord thread & a racial epithet, too. Lovely. Graham Cluley / @gcluley : So @jack has had his Twitter account hijacked. Everyone should ensure they have 2FA enabled, use unique password, and double check what apps they've linked to their accounts. Hard to say at moment how he was compromised, but one of those reasons most likely. Will Oremus / @willoremus : Twitter CEO @jack's account has been hacked, apparently by an entity called Chuckling Squad, which also recently hacked the accounts of YouTube stars James Charles and Shane Dawson, among others. https://www.insider.com/... https://twitter.com/... Eric Spencer / @justeric : Or he needed to get some things off his chest and obfuscated it with a bunch of other stuff that sounded “hacky.” https://twitter.com/... EducatdHillbilly / @robprovince : Was it? Are we sure of this? https://twitter.com/... Elizabeth Lopatto / @mslopatto : I see Twitter is responding to this with its typical competence https://twitter.com/... @chillmage : well it's official now: nobody is safe on Twitter https://twitter.com/... Tom Warren / @tomwarren : Amazing that it has taken 20+ mins for anyone at Twitter to even notice that their CEO's account has been hacked 🙄 https://twitter.com/... Kenneth Li / @kenli729 : Jack Dorsey's twitter hack is ...Sauvage. James Whatley / @whatleydude : Jack: 'We're committing Twitter to help increase the collective health, openness, and civility of public conversation' Users: BUT WHAT ABOUT THE NAZIS? Jack: pic.twitter.com/NXEVHgLclF
Context & Ripple Effects
The hack of Twitter's CEO didn't touch Twitter's systems: attackers gained control of the phone number tied to @jack through what Twitter calls a mobile provider security oversight, then composed tweets via text message. The claimed perpetrators, the Chuckle Squad, used the access to post a stream of racist tweets from the most-watched account on the platform.
The episode exposed a feature most users never think about — the ability to tweet by SMS — as an attack surface, and it set off a chain that later included the arrest of an alleged Chuckling Squad member and Krebs on Security's attribution to English SIM swapper Joseph James Connor, tying this incident into the broader SIM-swapping wave against high-value accounts.
First-order effects
- Twitter confirmed the compromise via @twittercomms, said its own systems showed no signs of intrusion, and moved to secure the account — while the SMS-to-tweet path through Cloudhopper remained a live question in the investigation.
- Jack Dorsey, as the platform's CEO, became the visible victim: the racist tweets posted under his name were amplified precisely because of who the account belongs to.
Second-order effects
- Within days Twitter temporarily turned off the SMS-to-tweet feature, removing a convenience for a small set of users to close a hole that let a compromised phone number control the CEO's account.
- The mobile provider's security oversight put carrier-side account security — SIM swaps and number porting — at the center of the story, shifting scrutiny from Twitter's defenses to the phone network's.
Third-order effects
- The pattern that later surfaced — an alleged SIM swapper linked to the attack — points to a structural weakness where control of a phone number substitutes for control of an account, pressuring platforms to deprecate SMS-based posting and recovery for high-profile users.
- As attribution and arrests followed the hack, it became a test case for whether law enforcement can reach the loosely organized groups behind SIM-swapping attacks on executives and public figures.
The trend: SIM swapping is emerging as the dominant way to hijack high-profile accounts, forcing platforms like Twitter to retire SMS-based controls and lean on carrier security they don't control.