Summary
On 15 July 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Jeff Bezos, and Apple all tweeted the same thing: send Bitcoin and I will send back double. It was a scam, and it ran from inside Twitter. Attackers had phoned a handful of Twitter employees, posed as IT, and talked them out of their credentials, which gave access to an internal admin tool that could take over any account on the platform. The mastermind turned out to be a 17-year-old. It is the lesson that a powerful internal "god-mode" tool is only as secure as the most socially-engineerable employee who can reach it.
How it happened
The attack was a coordinated phone spear-phishing (vishing) campaign that began on 14 July 2020. The attackers gathered details on their targets, called them while impersonating Twitter IT, and socially engineered them into handing over their credentials, capturing the login (and the multi-factor prompt) on a fake VPN page in real time. They first phished lower-level employees who could not reach the admin panel, then used those footholds to navigate internal systems and find staff who could. Those credentials unlocked the real prize: Twitter's internal account-management tool, a "god-mode" panel that could change any account's associated email address and reset or bypass its two-factor authentication.
With that tool, the per-user security of even the most famous accounts was irrelevant. The attackers targeted 130 accounts, tweeted from 45, accessed the direct-message inboxes of 36, and downloaded the full account archive for 7. From verified accounts belonging to presidents, billionaires, and major companies, they ran a simple Bitcoin-doubling scam and pulled in about $118,000 in a few hours before Twitter scrambled to lock things down, briefly preventing all verified accounts from tweeting at all.
The damage
The financial take, about $118,000, was almost the least alarming part. The same access could have moved markets or sparked a geopolitical incident, a fake announcement from a world leader's account, and the fact that it was "only" a crypto scam was something close to luck. Four people were ultimately charged, including the 17-year-old mastermind, Graham Ivan Clark, who pleaded guilty to a three-year sentence; a fourth defendant, the UK's Joseph O'Connor, was later extradited and sentenced to five years in US prison in 2023. New York regulators also found that Twitter had gone without a chief information security officer for the seven months before the hack. The episode exposed how few people, and how little protection around a single powerful tool, stood between social engineering and total control of the platform.
Why Twitter 2020 still matters
It is the internal-admin-tool plus social-engineering lesson. A "god-mode" tool that can take over any account is an enormous concentration of power, and if a phished employee can reach it, every user's own two-factor authentication is beside the point. The defences: require phishing-resistant MFA for employees, put powerful internal tools behind least privilege and multi-person approval for high-impact actions like account takeover, log and alert on every use of that tooling, and train staff against phone impersonation. It is the same social-engineering-to-internal-tools pattern later seen at MGM and Caesars.
How to fix it
- Cut access to the internal admin tool and reset credentials and sessions for affected employees; assume the tool was fully abused.
- Re-secure hijacked accounts (reset emails, force re-authentication) and review what account data was downloaded.
- Add approval, logging, and alerting to the admin tool before re-enabling it, so no single account can take over users silently.
How to avoid it
- Require phishing-resistant MFA (FIDO2/passkeys) for all employees; the entry point was phished credentials and a relayed MFA prompt.
- Put powerful internal tools behind least privilege, granular permissions, and multi-person approval for high-impact actions like account takeover.
- Log and alert on every use of admin or god-mode tooling, and rate-limit sensitive actions.
- Train staff against phone (vishing) impersonation, and give them a way to verify "IT" callers out of band.
References
Related vulnerabilities
All OpSec →- CRITICALOPSEC-MIDNIGHT-BLIZZARD-2024
In January 2024, Microsoft revealed that Russia's foreign-intelligence service, the same APT29 behind SolarWinds, had been reading the email of its senior leadership. The way in was almost insulting in its simplicity: a forgotten, non-production test account with a weak password and no MFA. The attackers guessed the password by spraying common ones across many accounts, then pivoted through a forgotten over-privileged application to grant themselves access to corporate mailboxes, including those of executives and the security and legal teams. It is the lesson that your security is only as strong as the account you forgot about, and that even Microsoft's perimeter fell to a missing MFA checkbox.
- CRITICALOPSEC-MGM-CAESARS-2023
In September 2023, two of the biggest names in Las Vegas, MGM Resorts and Caesars Entertainment, were brought to their knees, not by a sophisticated exploit, but by a phone call. The Scattered Spider group simply called the companies' IT help desks, impersonated employees, and talked the support staff into resetting their multi-factor authentication, handing the attackers a way in. From there they deployed ALPHV/BlackCat ransomware. Caesars paid about $15 million; MGM refused and took a roughly $100 million hit as slot machines, hotel keys, and check-in systems went dark for days. It is the lesson that the help desk is part of your attack surface, and that the most advanced MFA is undone by a human who can be convinced to reset it.
- CRITICALOPSEC-SNOWFLAKE-2024
In mid-2024, a single gap, accounts without multi-factor authentication, turned into one of the largest waves of data theft ever, hitting Ticketmaster, AT&T, Santander, and around 165 other companies at once. The attackers never broke Snowflake, the cloud data platform all of them used. They simply logged in with valid usernames and passwords, harvested months or years earlier by infostealer malware from employees' personal computers and bought on criminal markets. Where MFA was not turned on, a stolen password was a full key. It is the defining lesson of the infostealer era: your breach can start on an employee's home laptop, and MFA is the difference between a leaked password and a catastrophe.
- CRITICALOPSEC-23ANDME-2023
23andMe held the most personal data there is: people's DNA. In 2023 attackers got into more than 18,000 accounts and, through a single social feature, turned that into the genetic and ancestry data of roughly 6.9 million people. The break-in required no flaw in 23andMe at all. Attackers simply took username-and-password pairs leaked from other companies' breaches and tried them, betting, correctly, that people reuse passwords. The accounts had no MFA, and 23andMe did not notice the five-month wave of automated logins. From those footholds, the attackers scraped relatives' data through an opt-in feature, and the fallout, fines, a $50 million settlement, and ultimately bankruptcy and a fire-sale of the DNA database itself, shows that a breach can be fatal even when your own systems were never hacked.
- CRITICALOPSEC-LASTPASS-2022
LastPass is a password manager, the digital vault tens of millions of people trusted with every password they have. In 2022 attackers got into it, and the breach unfolded in a way that turned a developer's home computer into a path to those vaults. A first intrusion stole source code. The attackers used it to identify and target one of only four engineers who held the keys to production backups, planting a keylogger on his home PC through an unpatched flaw in, of all things, his Plex media server. With his master password captured, they exfiltrated backups of customers' encrypted password vaults. The encryption held, but anyone with a weak master password was now exposed to offline cracking at the attacker's leisure. It is the lesson that a vault is only as strong as the master password protecting it, and that your blast radius includes your engineers' home machines.
- HIGHOPSEC-UBER-2022
In September 2022, an 18-year-old broke into Uber and posted screenshots of its internal systems to prove it, an embarrassingly total compromise that started with a tactic anyone can fall for: pestering. The attacker, part of the Lapsus$ group, had a contractor's stolen password, and to get past multi-factor authentication, simply spammed the contractor with login-approval prompts until, worn down and then nudged over WhatsApp by the attacker posing as IT, they tapped "approve." Once inside, the attacker found a script with a hardcoded admin password that unlocked Uber's most powerful systems at once. It is the textbook lesson in MFA fatigue, and in how one hardcoded secret turns a foothold into a takeover.