Twitter Security Breach 2020: A Successful Social Engineering Attack

On July 15th, 2020, leading social media platform Twitter experienced a sophisticated cyber attack that caused untold disruption to the platform. The attack itself appears to be an example of social engineering attacks that plague businesses of all sizes around the world. This social engineering attack, combined with a simple bitcoin scam, will be talked about for years in information security.

2020 Twitter Breach Explained

In the breach, hackers gained access to the accounts of several high-profile Twitter users, including US presidential candidate Joe Biden, billionaire entrepreneur Jeff Bezos, and trillion-dollar tech company, Apple. The hackers used the access they gained to conduct a simple bitcoin scam. The access to such high-profile Twitter accounts took advantage of a coordinated social engineering attack on key Twitter employees, gaining access to internal systems.

So, here we have an interesting combination of incredible sophistication to gain access to internal systems and incredible simplicity to steal money. The simple bitcoin scam promised, via Tweets from verified accounts, that if people sent $1,000 worth of bitcoin to a particular bitcoin address, they’d get $2,000 in return.

twitter breach 2020

In response to the attack, Twitter blocked verified accounts from Tweeting completely for up to one hour. Verified Twitter accounts belong to people of public interest who have verified their authenticity. These people typically have hundreds of thousands of followers.

The dark beauty of this attack is that it took advantage of peoples’ trust in public figures. Most people would have the common sense not to send money to a random bitcoin address if a random account Tweeted that they could double their money.

However, when the accounts Tweeting about the money-making promises are verified figures of public trust, it is much easier to fall victim and believe the Tweet. It’s believed the bitcoin wallet’s balance grew rapidly to over $100,000 in value (~11 BTC at the time of the attack).

What is Social Engineering in Cyber Security?

Social engineering in cyber security is when an unknown or untrusted party gains the trust of someone inside a company. After the attacker gains the victim’s trust, they can use this trust for nefarious purposes, such as opening a back door into sensitive systems.

In the case of the 2020 Twitter breach, it appears that a coordinated and complex social engineering attack granted the access that the hackers needed to post from verified Twitter accounts. Social engineering attacks take advantage of the people within organizations rather than the systems used to secure a network.

The Twitter breach shows that even the people working for tech-oriented organizations are vulnerable to social engineering attacks. It also shows that even technically secure environments at the world’s largest enterprises are susceptible to intrusion.

Social Engineering Threats

The following are some of the main social engineering threats can arise from a successful attack:

  • Compromised users can open infected files that wreak havoc on an organization’s internal networks.
  • Victims can reveal confidential company information or personal information in a type of social engineering attack known as spear phishing.
  • Victims may click malicious URLs that infect their computer or every computer one network.
  • Victims might reveal passwords to sensitive databases, which attackers can retrieve and dump on the darknet or demand money for.
  • In a type of social engineering attack known as a watering hole attack, victims visit seemingly trustworthy websites and attackers either infect their computers or access internal networks.
  • Apply all these practices inside the corporate network and when working outside the office to improve endpoint security.

Social Engineering Prevention

Social engineering prevention is best achieved through thorough employee awareness and education about these types of attacks. More specifically, here are some prevention methods all employees and employers should follow:

  • Take a cautious approach to any communications that seem abnormal or unexpected even from people whom you trust
  • Ask people for proof of identity, such as documents or numbers that can easily be verified as authentic
  • When receiving phone calls, ask a colleague who recognizes the supposed caller’s voice to verify it
  • Think before clicking on any new or unfamiliar links.
  • Never download files you didn’t expect or when you don’t know the sender
  • Use multi-factor authentication for key systems so that a compromise in credentials doesn’t always result in a breach

Summary

Social engineering attacks exploit vulnerabilities in human psychology. The 2020 Twitter breach is an almost perfect example of how effective social engineering can be. An enterprise can take all the steps in the world to secure its network, but employees can still provide attackers with entry points into key systems. Prevention can only be achieved with increased employee education about social engineering.

1 thought on “Twitter Security Breach 2020: A Successful Social Engineering Attack”

Comments are closed.

Your subscription could not be saved. Please try again.
Your subscription has been successful.

RonanTheWriter Newsletter

Subscribe for recommended business tech solutions, reading resources, and exclusive tips. 

We use Sendinblue as our marketing platform. By Clicking below to submit this form, you acknowledge that the information you provided will be transferred to Sendinblue for processing in accordance with their terms of use