[Thread] Twitter says a “coordinated social engineering attack” against employees with access to internal systems and tools allowed hackers to hijack accounts
Our investigation is still ongoing but here's what we know so far:
@twittersupport
Context & Ripple Effects
Twitter's official statement confirms what its account-by-account tally had already implied: the July 15 hijacking of 130 high-profile accounts was not a credential leak but a phone spear phishing campaign aimed at the small set of employees who hold keys to Twitter's internal support and account-management tools.
The disclosure matters because it locates the failure inside the platform's own perimeter — whoever controls an employee's session inherits the ability to rewrite any account on the service, which is exactly how the attackers pushed tweets from a small subset of the targeted accounts.
First-order effects
The owners of the 130 targeted accounts face immediate exposure: beyond the fraudulent tweets, hackers reached the DM inbox of up to 36 of those accounts, putting private correspondence at risk while Twitter's investigation continues.
Twitter's own response is to clamp down on the attack surface — it has since limited employee access to the internal tools the phished staff could reach.
Second-order effects
Every platform whose support staff can silently take over user accounts now has to assume its employees are phishing targets too, pushing rivals toward the same least-privilege restrictions Twitter adopted after the breach.
The DM access findings give regulators and enterprise customers a concrete reason to question whether platform-held private messages are safe to treat as confidential, raising pressure on Twitter's business relationships built on direct-message intimacy.
Third-order effects
If the pattern holds, the industry's privileged 'god-mode' support consoles get redesigned around narrow authorization boundaries — segmented approvals, hardware keys, and audit trails — because a single phished operator proved capable of commandeering any account on the network.
The incident also accelerates the argument that platforms holding users' DMs are custodians of sensitive data with systemic blast radius, feeding the longer push for independent audits of insider-access practices.
The trend: Platform security is shifting from defending the login edge to hardening the small circle of insiders who wield account-control tools, after a single phished employee group demonstrated how much damage that access concentrates.
We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.
We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf. We're looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it.
We also limited functionality for a much larger group of accounts, like all verified accounts (even those with no evidence of being compromised), while we continue to fully investigate this.
Internally, we've taken significant steps to limit access to internal systems and tools while our investigation is ongoing. More updates to come as our investigation continues.
It's completely terrifying that, from the sound of these tweets, employees can use internal systems and tools to access and control the accounts of some of the highest profile, most powerful people in the world. https://twitter.com/...
This was disruptive, but it was an important step to reduce risk. Most functionality has been restored but we may take further actions and will update you if we do.
What if this is a coordinated effort of some sort to either a) move some money b) discredit Twitter c) create a claim in which you can then argue that powerful people should not be on Twitter?
Translated: a hacker tricked a Twitter employee. This is the service the President depends on to communicate, the service that can ruin people's lives, and their security is this bad. Is there anything Twitter can't fuck up? https://twitter.com/...
May I recommend the Information Assurance training the Navy did every.single.year? I mean, we all had the scenarios memorized after the 3rd time it was the same training, but the ridiculousness was memorable enough to be effective. https://twitter.com/...