Twitter confirms it inadvertently verified six “inauthentic” accounts, now suspended, after a user highlighted them
Six users with fake profile pics were seemingly verified less than one month after being created. — Questions have been raised over Twitter's verification process …
The Daily DotMikael Thalen
Context & Ripple Effects
Twitter had only recently resumed verification after an earlier pause, while a 2018 phishing ad had already shown how verification branding could be exploited. The six wrongly verified accounts turn a process-design concern into a visible trust failure.
Twitter suspended the six accounts, but the verified badge's credibility is immediately weakened for users judging whether an account is authentic.
Twitter's verification team faces pressure to tighten the checks that allowed recently created accounts with fake profile images to receive badges.
Second-order effects
Legitimate applicants face a less predictable path to verification as Twitter responds by pausing or restricting access to the application process.
Impostors and phishing operators benefit when users cannot reliably distinguish an official-looking verification signal from a compromised one, echoing Twitter's earlier verification-themed phishing ad failure.
Third-order effects
Repeated false verifications push account authentication toward more stringent, auditable workflow controls rather than a badge process that can be reopened without durable safeguards.
The episode illustrates that platform identity signals are only as trustworthy as the operational review behind them; failures can turn verification itself into an attack surface.
The trend: Social platforms are being forced to treat verification as a high-risk identity-control workflow, not merely a public-status feature.
Meet @aykacmis, @degismece, @anlamislar, @aykacti, @kayitlii, and @donmedim, a sextet of blue-check verified Twitter accounts created on June 16th, 2021. None has yet tweeted and all have roughly 1000 followers (and mostly the *same* followers). cc: @ZellaQuixote https://twitter.…
@noUpside @conspirator0 @ZellaQuixote cc @rinkisethi You might have a malicious or bribed insider. Something similar happened at IG (paid off by spammers, in that case).
I learned a little bit more about the @verified process. Twitter uses Unit21, which essentially uses machine learning to give a yes or no answer based on your submission info, and then a Twitter employee confirms. I obviously have no proof, but where there's ML there's bias.
According to B, there is no ML in the decision-making process - it's humans who are blatantly disregarding people who exceed the criteria for being verified while approving what are very clearly bot accounts. I'm pretty sure this is worse? https://twitter.com/...
Update: five of these six dubious verified accounts (along with the majority of the supporting botnet) have been suspended by Twitter. The sixth (@aykacmis) appears to have self-deactivated. https://twitter.com/...
Two of these six accounts (@kayitlii and @aykacti) have photographs of people as their profile pics. Despite the presence of the blue verification checkmark, neither image is likely to depict the account holder as both images appear to be stolen. https://twitter.com/...
@noUpside @conspirator0 @ZellaQuixote @rinkisethi UPDATE: I've heard they ruled out a malicious insider. Looking forward to hearing about what happened.
These six newly-created verified accounts have 977 followers in common. One is @verified (which follows all blue-check verified accounts). The other 976 were all created on June 19th or June 20th, 2021, and all follow the same 190 accounts. #Astroturf https://twitter.com/...
These 976 accounts are part of an astroturf botnet consisting of (at least) 1212 accounts. The network is split into followers, which follow the aforementioned verified accounts as well as other members of the botnet, and followees, which are followed by the other bots. https://t…
Fascinating stuff. The patterns here suggest this might be related to some service/insider or “method” for getting new accounts verified. https://twitter.com/...
Twitter must be like: Poor actors needs to hack themselves or buy already hacked verified accounts. Not good. How we could help them? What if we just start verifying their own (bot) accounts? Let's see! 🤦♂️ https://twitter.com/...
Twitter botched this entire process. Denial of verification seems completely arbitrary because what is this? What kind of algorithm did they create to give accounts like these verification, but not established ones? https://twitter.com/...
I know several academics, published, top of the disinfo and extremism field and thus targets for impersonation, who can't get verified. Not sure how this can happen! https://twitter.com/...
Fake bot accounts getting routinely verified sooner than established tweeters with large followings could indicate, as @alexstamos has astutely pointed out, the presence of insiders who are bribed to push the right buttons. I hope @TwitterSafety is putting those dots together. ht…