In an update to the July 15 hack, Twitter says a few employees were targeted in a phone spear phishing attack, and it had since limited access to internal tools
‘This attack relied on a significant and concerted attempt to mislead certain employees’ — Twitter provided an update …
The VergeJay Peters
Context & Ripple Effects
Two weeks after Twitter first disclosed a coordinated social engineering attack against its own staff, the company is filling in the mechanism: a few employees were reached by phone spear phishing, not a technical exploit, and the intruders used their access to hijack high-profile accounts.
Twitter's employees with access to internal account tools are now the named attack surface, and the company has responded by limiting that access — directly constraining how quickly those same teams can act on future account issues.
Second-order effects
Rival platforms face pressure to audit who on their own staff can touch user accounts and private messages, since the precedent here shows a handful of phoned employees were enough to expose DMs at scale.
Third-order effects
If insider-access restrictions become standard after this pattern of social engineering, platform incident response shifts toward least-privilege architectures for internal tools — trading operational speed for breach containment.
The trend: Platform security is moving from perimeter defense against external hackers toward hardening employee access to internal tools, as social engineering of staff becomes the preferred entry point.
We're sharing an update based on what we know today. We'll provide a more detailed report on what occurred at a later date given the ongoing law enforcement investigation and after we've completed work to further safeguard our service. https://blog.twitter.com/...
Update on the Twitter hack: * employees were the target of a “phone spear phishing attack” (a detail in our story Monday) * Twitter cutting the # of employees w/ access to security tools during investigation. Will be “slower to respond” in the meantime https://www.bloomberg.com/.…
Twitter has released more info about hack. The hackers “targeted a small number of employees through a phone spear phishing attack [and] used their credentials to access our internal systems and ... target additional employees who did have access to our account support tools.” ht…
It's terrible when this kind of thing happens but I am in awe of the response and transparency. Incredible people are working on this and I can say unequivocally that we have action behind every word. 👇 https://twitter.com/...
This is a WILDY different scenario than the initial “A Twitter employee was bribed to provide access to internal systems” story circulating in the media on the day. https://twitter.com/... https://twitter.com/...
Just another reminder that we are all vulnerable to social engineering attacks. The fascinating thing is that this was a two-pronged attack, with the first one letting them learn enough to successfully go deeper on the second attack. https://twitter.com/...