A person involved in Twitter hack may have gained access to Twitter's internal dashboard using credentials pinned in one of the company's Slack channels
one of whom says he lives at home with his mother ... 19 and lived in the south of England with his mother.” https://www.nytimes.com/... Eric Geller / @ericgeller : Wow. Just seeing this. Twitter says it believes the hackers breached all those high-profile accounts by tricking company employees into handing over their passwords. An embarrassing revelation that raises questions about how highly privileged employees protect their accounts. https://twitter.com/... Anthony DeRosa / @anthony : Good technical analysis of the Twitter hack: It seems that attackers were able to use the portal access to update the email address on file for the account, revoke any 2FA settings, and then do a password reset to gain access to the account. https://medium.com/... Aaron Stewart-Ahn / @somebadideas : In this version it really does look like one of the hacks of the century was by a bunch of bros who wasted it all on clout & bitcoin https://twitter.com/... MikeFarb / @mikefarb1 : Exactly. Far greater chance Bitcoin was the cover. If they were able to post on multiple accounts timelines they were in the account. DM's sitting right there. https://twitter.com/... Rachel Tobac / @racheltobac : Really interested to learn more in the weeds details of how attackers gained access to Twitter's admin panel. Here a hacker claimed they worked for Twitter but later switched their story and said they hacked into Twitter's Slack to get the creds and admin panel access. We'll see! https://twitter.com/... https://twitter.com/... Karissa Bell / @karissabe : Twitter keeping login credentials for this pinned to a slack channel is .. almost worse than the rogue employee scenario? Why would they not *at the very least* use a password manager?! https://twitter.com/... David Clinch / @davidclinchnews : First rule of sourcing information from anonymous self-proclaimed hackers: don't believe a word anonymous self-proclaimed hackers tell you...without receipts-Kate has the receipts still need to take some of what “Kirk” purportedly said about how he gained access with bags of salt https://twitter.com/... Mar Hicks / @histoftech : ok so twitter did the 2020 equivalent of leaving a post-it note on the monitor cool cool cool https://twitter.com/... Alex Stamos / @alexstamos : If true, this is no bueno. Enterprises usually have three sources of authentication for employees/contractors: 1) Credentials 2) MFA token (hard or soft) 3) A provisioned corporate device You should have all three to access user data or account controls, not just #1. https://twitter.com/... @yburyug : on why they went crypto scam and not diplomatic market manipulation via compromised accounts, it's cuz it was a young kid whose like 20 and another bored older script kiddy and pry just lacked the cleverness & were dumb enough to talk to the times about it https://www.nytimes.com/... Tom Robinson / @tomrobin : The #TwitterHack bitcoins have just started to move again - some being sent to ChipMixer Simultaneous movement of funds from two wallets that have received the hacker's bitcoins suggests they're still under the control of one person @elliptic #twitterscam #twitterhacked David S. Joachim / @davidjoachim : Twitter hack: “4 people at the center of the scheme spoke with The Times and shared numerous logs and screen shots of the conversations they had on Tuesday and Wednesday, demonstrating their involvement both before and after the hack became public https://www.nytimes.com/... https://twitter.com/... Julia Carrie Wong / @juliacarriew : i don't usually cover cybersecurity and everything about this story is freaking me out would really really really love to see twitter get cracking on e2ee for dms and slack get moving on it too https://www.nytimes.com/... @sanjaykalra : This #cyberattack is most disturbing not because it was sophisticated or well coordinated by powerful actors, but the opposite - cheaply done by amateurs. Wake up call for all Internet companies to improve defenses-technologically, people & process-wise. https://www.nytimes.com/... Dave Agar / @dave1agar : “it was done by a group of young people — one of whom says he lives at home with his mother — who got to know one another because of their obsession with owning early or unusual screen names, particularly one letter or number” https://www.nytimes.com/... Matthew Reichbach / @fbihop : Started as “hey, we should take over and sell these one-character name accounts” and ended up with “let's scam bitcoin by using accounts of celebrities and other powerful people!” Quantian / @quantian1 : @modestproposal1 I am skeptical about this. There's almost certainly nothing of value in the DMs for blackmail, and if you tried to do a public stock pump the SEC could investigate/stop wires. Maybe you could try and mess with FX and use some shady Caymans broker and lots of leverage? Anastasia Golovashkina / @golovashkina : Remember LulzSec in 2011? Reminds me of that. https://www.nytimes.com/... Aaron Pressman / @ampressman : Kids say the damnedest things - Instead, it was done by a group of young people — one of whom says he lives at home with his mother — who got to know one another because of their obsession with owning early or unusual screen names, particularly one letter or number, like @y or @6 Staci D Kramer / @sdkstl : >>The hacker who received the message, using the screen name “lol,” decided over the next 24 hours that Kirk did not actually work for Twitter because he was too willing to damage the company.<< https://www.nytimes.com/... Tom Warren / @tomwarren : I love that the New York Times interviewed someone named “lol” and another called “ever so anxious,” on Discord, about the Twitter hack https://www.nytimes.com/... Haseeb Awan / @haseeb : Here is what happened as per my info. Hacker met a twitter employee on discord gaming channel and befriended him who sold him his login for 2000. Hacker then replaced emails through this tool & removed 2FA. Rest you guys know ! https://twitter.com/... Scott Stedman / @scottmstedman : We live in the dumbest timeline. “the attack was not the work of a nation-state or a sophisticated group of hackers. Instead, it was done by a group of young people — one of whom says he lives at home with his mother” https://www.nytimes.com/... Jacob Rubashkin / @jacobrubashkin : The Times talked to four people they say were behind the Great Twitter Hack of July 2020: a bunch of 20-somethings who planned the attack on Discord and then got nervous when one person went rogue and took over high-profile accounts. https://www.nytimes.com/... @brendandburns : “Mr. O'Connor said other hackers had informed him that Kirk got access to the Twitter credentials when he found a way into Twitter's internal Slack messaging channel and saw them posted there” Production creds in Slack is a scary (but very real) thing https://www.nytimes.com/... @spyblog : Is #STFU no longer part of #hacker #OPSEC ?? Keeping chat log files & talking to the press = prosecution & extradition, if they are lucky. Worse if they accessed sensitive DMs of billionaires “Hackers Tell the Story of the Twitter Attack From the Inside” https://www.nytimes.com/... https://twitter.com/... @rdrv3 : Don't know if I buy Twitter's account of this being social engineering. Did a contractor or someone's kid get access to something they shouldn't have? I am starting to think this will be revealed as far more embarrassing for Twitter than anyone could have originally imagined. Kate Conger / @kateconger : Funnily enough, some of his middlemen claimed to be asleep when all this action was taking place! One of them provided screenshots of texts with his girlfriend, saying he was going to take a nap, to corroborate his story. Martin Sfp Bryant / @martinsfp : “The [Twitter hack] was done by a group of young people — one of whom says he lives at home with his mother — who got to know one another because of their obsession with owning early or unusual screen names” https://www.nytimes.com/... Zack Whittaker / @zackwhittaker : Can confirm much of this @kateconger and @nathanielpopper scoop, which adds more on the Twitter account hacks. Lines up with what I've been told by one well-placed source. https://www.nytimes.com/... Tom Gara / @tomgara : Huge validation here for the they're-mostly-just-idiots theory of history https://www.nytimes.com/... https://twitter.com/... https://twitter.com/... @scottmelker : I told you guys @haseeb was a genius. He figured out the entire hack and delivered the hackers directly to the New York Times. https://www.nytimes.com/... Eamon Javers / @eamonjavers : The critical failure in the most damaging attacks against the United States has been of imagination. In '01 and '16, we didn't anticipate that airplanes could be suicide missiles, or Facebook posts could manipulate democracy. These were zero-day attacks of social engineering. https://twitter.com/... Eric Geller / @ericgeller : Every answer raises more questions. What does “in some way” mean? Were some accounts used for things other than tweeting the Bitcoin scam? I foresee more stern lawmaker letters. https://twitter.com/... Eric Geller / @ericgeller : Per NYT, Twitter still doesn't actually know if the hackers got an employee's credentials by socially engineering them (as Twitter initially said) or bribing them (as @josephfcox later reported). https://www.nytimes.com/... https://twitter.com/...
Here's what we know: Someone going by the name Kirk got access to Twitter's internal dashboard. He claimed to be a Twitter employee, but later claimed he hacked into Twitter's Slack channel and found login credentials pinned there.
the Twitter hacker reportedly got access to Twitter's admin panel by finding login credentials pinned inside a Twitter Slack channel. If that's true then holy shit. https://www.nytimes.com/... https://twitter.com/...
*BREAKING NEWS* - Elliptic Identifies Likely Use of Wasabi Wallet Service to Launder #TwitterHack Bitcoins For more information visit our blog ➡️ https://www.elliptic.co/... #followthemoney #ellipticaml #crypto #cryptoscam #twitter #bitcoin
New business idea: @SlackHQ Honey Channels. Create new slack channels that should only attract intruders (e.g. #adminpasswords). Automatically lockout any account that joins and trigger an IR investigation. @Lerg & @Maliciouslink I will take all the money now. https://twitter.com…
I expect the hackers will make a mistake as Wasabi has no postmix spending tools. Probably get caught and go to jail. (Won't be the first time someone gets caught as a result of using a 🍌 mix) https://twitter.com/...
Fascinating read - This NYT post on the Twitter hack explains “OG usernames”, the social media username equivalent of domain squatting! Q: “OG usernames usually a short word/number (eg @y @6) are hotly desired, snapped up by early adoptrs to resell later” https://www.nytimes.com/…
This is incredible reporting. To think that we know so much, so soon. And yet... not the identity of the hacker who actually did it, or how they got in. Not yet. https://twitter.com/...
If true, this is quite a story. It's a tale of opportunistic and mediocre hackers (hardly criminal masterminds) who got lucky and took advantage of Twitter's incompetent security. There's a lesson here for us all. https://twitter.com/...
How much of the online world is just fundamentally insecure? Occasionally a hobbyist does something visible like this and we hear about it, but it is frighteningly easy for state actors to do less visible things. https://twitter.com/...
1) who is sharing creds in SLACK?! i cannot. i was giving twitter a lot of leeway, the pwn comes for us all in the end, but this? this is too much. 2) why did “kirk” appear for this hack then disappear right after? (who is he?) 3) how did “kirk” get access to the twitter slack? h…
If true, i'm not sure why that is surprising. Anyone who's ever worked in IT know that all of our system for the most part are still run by humans. Humans do stuff like this ALL THE TIME lol https://twitter.com/...
Hackers involved in the Twitter breach said it started as a quest for cool usernames. Then one member of the group began going after cryptocurrency companies, Jeff Bezos, and Kanye West. w/@nathanielpopper https://www.nytimes.com/...
Nice scoop - even if it isn't the most exciting narrative behind such a huge hack. If you're at Twitter security this has to be galling that kids/young adults chatting shit with each other on Discord caused such a huge event. https://twitter.com/...
When he woke up, Kirk was gone. He'd made off with about $180,000 in bitcoin. Here's our updated story with all the details: https://www.nytimes.com/...
Real talk: if you gain control of the most important accounts in the world and only make $113K you should be arrested for being the most incompetent crook of all time. “Here's the key to bank vault. Take whatever” “No thanks, give us those pens, the coffeemate and 3 notepads” htt…
Twitter: “We detected what we believe to be a coordinated social engineering attack.” NYTimes: “done by a group of young people — one of whom says he lives at home with his mother ... 19 and lived in the south of England with his mother.” https://www.nytimes.com/...
Wow. Just seeing this. Twitter says it believes the hackers breached all those high-profile accounts by tricking company employees into handing over their passwords. An embarrassing revelation that raises questions about how highly privileged employees protect their accounts. htt…
Good technical analysis of the Twitter hack: It seems that attackers were able to use the portal access to update the email address on file for the account, revoke any 2FA settings, and then do a password reset to gain access to the account. https://medium.com/...
In this version it really does look like one of the hacks of the century was by a bunch of bros who wasted it all on clout & bitcoin https://twitter.com/...
Exactly. Far greater chance Bitcoin was the cover. If they were able to post on multiple accounts timelines they were in the account. DM's sitting right there. https://twitter.com/...
Really interested to learn more in the weeds details of how attackers gained access to Twitter's admin panel. Here a hacker claimed they worked for Twitter but later switched their story and said they hacked into Twitter's Slack to get the creds and admin panel access. We'll see!…
Twitter keeping login credentials for this pinned to a slack channel is .. almost worse than the rogue employee scenario? Why would they not *at the very least* use a password manager?! https://twitter.com/...
First rule of sourcing information from anonymous self-proclaimed hackers: don't believe a word anonymous self-proclaimed hackers tell you...without receipts-Kate has the receipts still need to take some of what “Kirk” purportedly said about how he gained access with bags of salt…
If true, this is no bueno. Enterprises usually have three sources of authentication for employees/contractors: 1) Credentials 2) MFA token (hard or soft) 3) A provisioned corporate device You should have all three to access user data or account controls, not just #1. https://twit…
on why they went crypto scam and not diplomatic market manipulation via compromised accounts, it's cuz it was a young kid whose like 20 and another bored older script kiddy and pry just lacked the cleverness & were dumb enough to talk to the times about it https://www.nytimes.com…
The #TwitterHack bitcoins have just started to move again - some being sent to ChipMixer Simultaneous movement of funds from two wallets that have received the hacker's bitcoins suggests they're still under the control of one person @elliptic #twitterscam #twitterhacked
Twitter hack: “4 people at the center of the scheme spoke with The Times and shared numerous logs and screen shots of the conversations they had on Tuesday and Wednesday, demonstrating their involvement both before and after the hack became public https://www.nytimes.com/... http…
i don't usually cover cybersecurity and everything about this story is freaking me out would really really really love to see twitter get cracking on e2ee for dms and slack get moving on it too https://www.nytimes.com/...
This #cyberattack is most disturbing not because it was sophisticated or well coordinated by powerful actors, but the opposite - cheaply done by amateurs. Wake up call for all Internet companies to improve defenses-technologically, people & process-wise. https://www.nytimes.com/.…
“it was done by a group of young people — one of whom says he lives at home with his mother — who got to know one another because of their obsession with owning early or unusual screen names, particularly one letter or number” https://www.nytimes.com/...
Started as “hey, we should take over and sell these one-character name accounts” and ended up with “let's scam bitcoin by using accounts of celebrities and other powerful people!”
@modestproposal1 I am skeptical about this. There's almost certainly nothing of value in the DMs for blackmail, and if you tried to do a public stock pump the SEC could investigate/stop wires. Maybe you could try and mess with FX and use some shady Caymans broker and lots of leve…
Kids say the damnedest things - Instead, it was done by a group of young people — one of whom says he lives at home with his mother — who got to know one another because of their obsession with owning early or unusual screen names, particularly one letter or number, like @y or @6
>>The hacker who received the message, using the screen name “lol,” decided over the next 24 hours that Kirk did not actually work for Twitter because he was too willing to damage the company.<< https://www.nytimes.com/...
I love that the New York Times interviewed someone named “lol” and another called “ever so anxious,” on Discord, about the Twitter hack https://www.nytimes.com/...
Here is what happened as per my info. Hacker met a twitter employee on discord gaming channel and befriended him who sold him his login for 2000. Hacker then replaced emails through this tool & removed 2FA. Rest you guys know ! https://twitter.com/...
We live in the dumbest timeline. “the attack was not the work of a nation-state or a sophisticated group of hackers. Instead, it was done by a group of young people — one of whom says he lives at home with his mother” https://www.nytimes.com/...
The Times talked to four people they say were behind the Great Twitter Hack of July 2020: a bunch of 20-somethings who planned the attack on Discord and then got nervous when one person went rogue and took over high-profile accounts. https://www.nytimes.com/...
“Mr. O'Connor said other hackers had informed him that Kirk got access to the Twitter credentials when he found a way into Twitter's internal Slack messaging channel and saw them posted there” Production creds in Slack is a scary (but very real) thing https://www.nytimes.com/...
Is #STFU no longer part of #hacker #OPSEC ?? Keeping chat log files & talking to the press = prosecution & extradition, if they are lucky. Worse if they accessed sensitive DMs of billionaires “Hackers Tell the Story of the Twitter Attack From the Inside” https://www.nytimes.com/.…
Don't know if I buy Twitter's account of this being social engineering. Did a contractor or someone's kid get access to something they shouldn't have? I am starting to think this will be revealed as far more embarrassing for Twitter than anyone could have originally imagined.
Funnily enough, some of his middlemen claimed to be asleep when all this action was taking place! One of them provided screenshots of texts with his girlfriend, saying he was going to take a nap, to corroborate his story.
“The [Twitter hack] was done by a group of young people — one of whom says he lives at home with his mother — who got to know one another because of their obsession with owning early or unusual screen names” https://www.nytimes.com/...
Can confirm much of this @kateconger and @nathanielpopper scoop, which adds more on the Twitter account hacks. Lines up with what I've been told by one well-placed source. https://www.nytimes.com/...
I told you guys @haseeb was a genius. He figured out the entire hack and delivered the hackers directly to the New York Times. https://www.nytimes.com/...
The critical failure in the most damaging attacks against the United States has been of imagination. In '01 and '16, we didn't anticipate that airplanes could be suicide missiles, or Facebook posts could manipulate democracy. These were zero-day attacks of social engineering. htt…
Every answer raises more questions. What does “in some way” mean? Were some accounts used for things other than tweeting the Bitcoin scam? I foresee more stern lawmaker letters. https://twitter.com/...
Per NYT, Twitter still doesn't actually know if the hackers got an employee's credentials by socially engineering them (as Twitter initially said) or bribing them (as @josephfcox later reported). https://www.nytimes.com/... https://twitter.com/...