/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

[Thread] Twitter says a “coordinated social engineering attack” against employees with access to internal systems and tools allowed hackers to hijack accounts

Our investigation is still ongoing but here's what we know so far:

@twittersupport

Context & Ripple Effects

This thread is Twitter's first public accounting of the July 15 hijacking of high-profile accounts, and it locates the breach not in any code flaw but in people: attackers ran a coordinated social engineering attack against employees who hold access to internal systems and account tools.

The disclosure opened a two-week drip of admissions that kept widening the blast radius — from an initial count of 130 affected accounts, to confirmation that hackers read the DM inboxes of up to 36 of those accounts, to a final attribution of the entry point to a phone spear-phishing campaign against a handful of staff, after which Twitter limited access to its internal tools.

First-order effects

  • Twitter's own support channel confirms the compromise path ran through employees with privileged internal access, meaning every high-profile account holder on the platform was exposed through Twitter's staff credentials rather than their own passwords.
  • The attackers obtained control of a small subset of the targeted accounts and sent tweets from them, forcing Twitter into incident-response mode across security, legal, and communications simultaneously.

Second-order effects

  • Once the scope became clear, Twitter restricted employee access to internal tools — a direct cost imposed on its own trust-and-safety and support workflows, which now operate with tighter controls and slower tooling.
  • The revelation that DMs were readable turns this from a defacement story into a data-exposure story, raising the stakes for regulators and enterprise users who treat DM archives as sensitive business records.

Third-order effects

  • If the pattern holds, insider-access control becomes the defining security surface for platform companies: the perimeter is no longer code but the humans authorized to act on accounts at scale, pushing the industry toward least-privilege tooling and audited internal authorization boundaries.
  • A single point of internal control capable of rewriting any account's output shows how much structural power platforms concentrate in administrative tools — a concentration that invites both regulatory scrutiny of platform governance and hardening of the identity and authorization layers behind user-facing products.

The trend: Platform breaches are shifting from perimeter exploits to human-targeted attacks on privileged internal tooling, making insider authorization the new battleground for account security.

Discussion

  • @twittersupport @twittersupport on x
    We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.
  • @twittersupport @twittersupport on x
    We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf. We're looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it.
  • @jason_koebler Jason Koebler on x
    we spoke to two hackers and we were able to independently verify they were in control of hijacked accounts today. One of them said they paid the Twitter employee to help them take over accounts; not sure on the specifics here at the moment
  • @jason_koebler Jason Koebler on x
    Anyone who tried to change their password in the wake of the hacks yesterday is locked out and Twitter has given no timeline to recover their accounts https://www.vice.com/...
  • @twittersupport @twittersupport on x
    We also limited functionality for a much larger group of accounts, like all verified accounts (even those with no evidence of being compromised), while we continue to fully investigate this.
  • @twittersupport @twittersupport on x
    Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.
  • @twittersupport @twittersupport on x
    We have locked accounts that were compromised and will restore access to the original account owner only when we are certain we can do so securely.
  • @ericgeller Eric Geller on x
    Per NYT, Twitter still doesn't actually know if the hackers got an employee's credentials by socially engineering them (as Twitter initially said) or bribing them (as @josephfcox later reported). https://www.nytimes.com/... https://twitter.com/...
  • @twittersupport @twittersupport on x
    Internally, we've taken significant steps to limit access to internal systems and tools while our investigation is ongoing. More updates to come as our investigation continues.
  • @neerajka Neeraj K. Agrawal on x
    Here's a timeline of the hack that shows it starting with cryptocurrency accounts and fanning out from there. It supports my “idiots running wild” theory https://www.theblockcrypto.com/ ... https://twitter.com/...
  • @tsunamino Danielle Leong on x
    This is actually a fairly normal support tool and often how support is able to diagnose problems. It's typically auditable and go through multiple layers of access checks. If anything, this shows you should always invest in internal tools for support https://twitter.com/...
  • @jamesrbuk James Ball on x
    The Twitter hack feels like someone breaking into a bank vault and then just using their WiFi to send 419 scam emails. Its potential vs what they seem to have got from it just do not align.
  • @janaktvu Jana Katsuyama on x
    Still waiting for answers from Twitter press team about the #twitterhacked investigation...How many accounts known to be compromised so far? When and how did Twitter become aware of this security breach? Will they be implementing any new safeguards? https://twitter.com/...
  • @carnage4life Dare Obasanjo on x
    This is like being terrified that cashiers at your bank have access to your money. https://twitter.com/...
  • @susanthesquark Susan Fowler on x
    It's completely terrifying that, from the sound of these tweets, employees can use internal systems and tools to access and control the accounts of some of the highest profile, most powerful people in the world. https://twitter.com/...
  • @twittersupport @twittersupport on x
    This was disruptive, but it was an important step to reduce risk. Most functionality has been restored but we may take further actions and will update you if we do.
  • @vitalikbuterin Vitalik.Eth on x
    “Centralized backdoors are awesome and help keep society safe” https://twitter.com/...