Two former Twitter employees say more than 1,000 staff and contractors had access to internal tools to change account settings and ownership as of early 2020
SAN FRANCISCO (Reuters) - More than a thousand Twitter employees and contractors as of earlier this year had access to internal tools …
Reuters
Context & Ripple Effects
This report lands days after the coordinated social engineering attack that let hackers hijack high-profile accounts via employees with internal access — the first public proof that those tools are an attack surface, not just an administrative convenience. It also extends a pattern reporters have documented before: as far back as 2017, sources described how hundreds at Twitter could use internal tools to shut down accounts, including deletions similar to Trump's.
What's new here is scale and specificity — former employees put the number above 1,000 staff and contractors who could change account settings and ownership as of early 2020, and follow-up reporting details multiple warnings to Dorsey since 2015 plus bogus help requests used to snoop. Screenshots of the internal control panel circulated mid-July show exactly what that access looks like.
First-order effects
Twitter faces immediate pressure to shrink and segment who can touch account settings and ownership, after the breach demonstrated that social-engineering one employee with tool access translates directly into account takeovers.
Second-order effects
Advertisers and high-profile users reassess platform risk on Twitter specifically, while rivals can market tighter internal-access controls as a differentiator for accounts whose value depends on authenticity — verification and account integrity become competitive features, not back-office plumbing.
Third-order effects
If the pattern holds, insider-access governance becomes a regulated expectation for consumer platforms: audits of privileged-tool access, least-privilege design, and disclosure of how many staff can alter user accounts shift from engineering hygiene to compliance requirements.
The trend: Platform security is moving from perimeter defense toward governing privileged employee access to user accounts, as insider tools prove to be the softest attack surface on major social networks.
Years ago Julian Assange warned @jack to “stay out of the censorship game.” Now @Twitter has given hundreds of people - including 3rd party contractors like @cognizant - access to their “god panel” to enforce censorship rules. The results are predictable. https://www.reuters.com/…
“More than a thousand Twitter employees and contractors as of earlier this year had access to internal tools that could change user account settings and hand control to others, two former employees said."https://www.reuters.com/ ...
There's an important concept in privacy and infosec called “role-based access control” (RBAC). With RBAC, you restrict data access to only those employee roles that actually need access. Why did 1,000 employees and contractors have this much unguarded access at Twitter? https://t…
“The former employees familiar with Twitter security practices said that too many people could have done the same thing, more than 1,000 as of earlier in 2020, including some at contractors like Cognizant.” Contractor admin privileges are especially risky. https://www.reuters.com…
We believe that for up to 36 of the 130 targeted accounts, the attackers accessed the DM inbox, including 1 elected official in the Netherlands. To date, we have no indication that any other former or current elected official had their DMs accessed.
E2EE for DMs is overdue. 2019: Saudi agents at Twitter got caught spying on 1000s of users 2020: Twitter employees got socially engineered, leading to this hack If Biden's DMs weren't hit, we avoided a Podesta moment by DUMB LUCK. Insider threat is why other tech cos. use E2EE. h…
Dutch far-right politician Geert Wilders confirms Twitter has told him that DMs were sent from his hacked account, and that he has concerns for the safety of some of those who messaged him https://www.bbc.co.uk/...