Twitter says around 130 accounts were affected in Wednesday's hack, and the attackers gained control of and sent tweets from a subset of those accounts
- “We believe approximately 130 accounts were targeted by the attackers in some way as part of the incident," Twitter said Thursday.
CNBCRyan Browne
Context & Ripple Effects
Twitter's disclosure narrows the picture of Wednesday's incident: a coordinated social engineering attack targeted employees with access to internal systems and tools, and roughly 130 accounts were touched in some way — though only a subset were actually taken over to send tweets.
The number matters because the blast radius kept growing after the fact: within a week, Twitter confirmed attackers also read the DM inbox for up to 36 of those 130 accounts, turning an account-takeover story into a private-message exposure story. The company's own incident overview laid out how the intrusion happened, what was accessed, and its next steps.
First-order effects
Owners of the targeted high-profile accounts face two distinct exposures — hijacked posting on one hand, and for the up-to-36-account subset, attackers reading their direct messages.
Second-order effects
Each successive disclosure reopens the story rather than closing it, so Twitter's crisis posture shifts from containment to repeated scope expansion — and the fact that employee-accessible tools were the entry point puts internal admin controls, not just user passwords, at the center of scrutiny.
Third-order effects
If the pattern holds, large consumer platforms will be pushed to treat privileged internal tooling as a governed surface — logged, least-privilege, and auditable — because the compromise of one support tool scaled directly into a global broadcast and a private-message breach.
The trend: Platform security is shifting its perimeter from user credentials toward employee-accessible internal tools, with disclosure scope expanding as forensic findings accumulate.
Based on what we know right now, we believe approximately 130 accounts were targeted by the attackers in some way as part of the incident. For a small subset of these accounts, the attackers were able to gain control of the accounts and then send Tweets from those accounts.
Wow. Just seeing this. Twitter says it believes the hackers breached all those high-profile accounts by tricking company employees into handing over their passwords. An embarrassing revelation that raises questions about how highly privileged employees protect their accounts. htt…
Twitter says about 130 accounts were targeted in a cyber attack this week. The company added that it was continuing to assess whether the attackers were able to access private data of the targeted accounts https://www.reuters.com/... https://twitter.com/...
130 #BlueChecks were affected in the #twitterhack The source was the same OG Users forum that hacked my #IGChris account a couple years ago using a similar account reset email interception. https://www.theguardian.com/ ... https://twitter.com/...
With the FBI poking around Twitter, it's a good time to remind people—don't have sensitive conversations in Twitter DMs. Move that stuff to Signal. You don't know who'll be in charge of Twitter five, ten, or twenty years from now. Remember the example of LiveJournal. https://twit…
Still waiting for answers from Twitter press team about the #twitterhacked investigation...How many accounts known to be compromised so far? When and how did Twitter become aware of this security breach? Will they be implementing any new safeguards? https://twitter.com/...