[Thread] Twitter says a “coordinated social engineering attack” against employees with access to internal systems and tools allowed hackers to hijack accounts
Our investigation is still ongoing but here's what we know so far:
@twittersupport
Context & Ripple Effects
This thread is Twitter's first public accounting of the July 15 hijacking of high-profile accounts, and it locates the breach not in any code flaw but in people: attackers ran a coordinated social engineering attack against employees who hold access to internal systems and account tools.
Twitter's own support channel confirms the compromise path ran through employees with privileged internal access, meaning every high-profile account holder on the platform was exposed through Twitter's staff credentials rather than their own passwords.
The attackers obtained control of a small subset of the targeted accounts and sent tweets from them, forcing Twitter into incident-response mode across security, legal, and communications simultaneously.
Second-order effects
Once the scope became clear, Twitter restricted employee access to internal tools — a direct cost imposed on its own trust-and-safety and support workflows, which now operate with tighter controls and slower tooling.
The revelation that DMs were readable turns this from a defacement story into a data-exposure story, raising the stakes for regulators and enterprise users who treat DM archives as sensitive business records.
Third-order effects
If the pattern holds, insider-access control becomes the defining security surface for platform companies: the perimeter is no longer code but the humans authorized to act on accounts at scale, pushing the industry toward least-privilege tooling and audited internal authorization boundaries.
A single point of internal control capable of rewriting any account's output shows how much structural power platforms concentrate in administrative tools — a concentration that invites both regulatory scrutiny of platform governance and hardening of the identity and authorization layers behind user-facing products.
The trend: Platform breaches are shifting from perimeter exploits to human-targeted attacks on privileged internal tooling, making insider authorization the new battleground for account security.
We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.
We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf. We're looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it.
we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take over accounts; not sure on the specifics here at the moment
Anyone who tried to change their password in the wake of the hacks yesterday is locked out and Twitter has given no timeline to recover their accounts https://www.vice.com/...
We also limited functionality for a much larger group of accounts, like all verified accounts (even those with no evidence of being compromised), while we continue to fully investigate this.
Per NYT, Twitter still doesn't actually know if the hackers got an employee's credentials by socially engineering them (as Twitter initially said) or bribing them (as @josephfcox later reported). https://www.nytimes.com/... https://twitter.com/...
Internally, we've taken significant steps to limit access to internal systems and tools while our investigation is ongoing. More updates to come as our investigation continues.
Here's a timeline of the hack that shows it starting with cryptocurrency accounts and fanning out from there. It supports my “idiots running wild” theory https://www.theblockcrypto.com/ ... https://twitter.com/...
This is actually a fairly normal support tool and often how support is able to diagnose problems. It's typically auditable and go through multiple layers of access checks. If anything, this shows you should always invest in internal tools for support https://twitter.com/...
The Twitter hack feels like someone breaking into a bank vault and then just using their WiFi to send 419 scam emails. Its potential vs what they seem to have got from it just do not align.
Still waiting for answers from Twitter press team about the #twitterhacked investigation...How many accounts known to be compromised so far? When and how did Twitter become aware of this security breach? Will they be implementing any new safeguards? https://twitter.com/...
It's completely terrifying that, from the sound of these tweets, employees can use internal systems and tools to access and control the accounts of some of the highest profile, most powerful people in the world. https://twitter.com/...
This was disruptive, but it was an important step to reduce risk. Most functionality has been restored but we may take further actions and will update you if we do.