More Than 1,000 People Could Access Twitter’s ‘God Mode’

Published at: July 24, 2020

More than 1,000 Twitter employees and contractors had access to the internal admin panel that enabled last week’s Twitter hack of 130 high profile accounts.

According to Reuters on July 24, two former employees have shed light on just how vulnerable Twitter’s security was — and may still be. They said that, in addition to employees, contractors like Cognizant could also have access.

Former chief security officer at AT&T Edward Amoroso, told Reuters that such powerful controls should not be available to so many people.

“That sounds like there are too many people with access,” he said, adding that staff should have limited rights with responsibilities split up as well as multiple checks and balances in place for adjusting sensitive information.

“In order to do cyber security right, you can’t forget the boring stuff.”

What happened?

On July 15 attackers accessed Twitter’s admin panel allowing them to take control of any Twitter account, post tweets from them and access personal information including private messages.

They posted scam Bitcoin (BTC) ‘giveaways’, by promising to send back double any sum received. All told, the scammers got away with around 12 BTC.

High profile accounts taken over include Tesla founder Elon Musk, former United States President Barack Obama, Amazon owner Jeff Bezos, Microsoft co-founder Bill Gates and 2020 U.S. presidential candidate and former Vice-President Joe Biden. Other celebrities, politicians and top business personalities also lost control of their accounts.

Twitter and the FBI are working together to investigate the breach, with regular updates from Twitter on their findings. On Jul 23, the company revealed that in “up to 36 of the 130 targeted accounts, the attackers accessed the DM inbox, including 1 elected official in the Netherlands.”

To recap:🔹130 total accounts targeted by attackers🔹45 accounts had Tweets sent by attackers🔹36 accounts had the DM inbox accessed🔹8 accounts had an archive of “Your Twitter Data” downloaded, none of these are Verified

— Twitter Support (@TwitterSupport) July 23, 2020

Twitter has also revealed they are looking for a new security head in order to improve security and employee training.

Security experts are concerned that the required upgrades to Twitter’s security and processes may not be complete before the U.S. elections on Nov. 3 with other countries potentially having the ability to manipulate the outcome through social media account take-overs.

Network security company Tenable founder Ron Gula asked:

“Does Twitter do enough to prevent account takeovers for our presidential candidates and news outlets when faced with sophisticated threats that leverage whole-of-nation approaches?”

Tags
Related Posts
Bill Gates warns Bitcoin buyers: If you have less money than Elon Musk, watch out
Microsoft founder Bill Gates has issued a warning to would-be Bitcoin (BTC) buyers looking to follow Elon Musk’s investment strategy. Speaking to Bloomberg’s Emily Chang, Gates suggested Musk had access to sophisticated trade management techniques that the average investor isn’t privy to. When asked about the susceptibility of Bitcoin to tumble in price in reaction to a mere tweet — undoubtedly a reference to Musk’s own social media posts — Gates said Musk was probably insulated from such market crashes: “Elon has tons of money and he’s very sophisticated so, you know, I don’t worry that his Bitcoin would randomly …
Technology / Feb. 23, 2021
Twitter, GameStop… enough! The world needs true decentralization
GameStop and Twitter are both a mirage and an iceberg — but don’t try tweeting that. Not because you won’t own the tweet (because you won’t), but because the only completely true expression that Twitter is capable of delivering as a platform is unlocking the ugly truth about the internet itself. Or as Elon Musk recently tweeted: In retrospect, it was inevitable — Elon Musk (@elonmusk) January 29, 2021 Let me explain. In the midst of Robinhood halting trading for its supposed users, Jack Dorsey has been talking about decentralizing Twitter and social media in general. But other than a …
Decentralization / Feb. 6, 2021
Crypto Twitter Responds to the Twitter Hack
Earlier this morning, a large-scale Twitter attack took over some of the most powerful verified Twitter accounts including Joe Biden, Elon Musk, Bill Gates, Kanye West, Kim Kardashian, Wiz Khalifa, Warren Buffett, Mike Bloomberg, Barack Obama, and Jeff Bezos. The attacker has posted about fake giveaways from the compromised accounts, asking for Bitcoin (BTC) payments and promising to send back double the amount received. Official Responses Many of the accounts were quick to respond to the hack with the Tweets being deleted and Twitter temporarily locking down all verified accounts until the situation has been resolved. Twitter Support said: “We …
Bitcoin / July 16, 2020
Twitter's crypto price index feature expands to 30 tokens and counting
Twitter has quietly expanded its new crypto feature that enables users to search the price of individual tokens, adding at least another 30 tokens. The new additions are part of the social media giant's "$Cashtags" feature which was announced by the Twitter Business account on Dec. 21 with the news Bitcoin (BTC) and Ether (ETH) were the first to be part of the new feature. Tweeting or searching for a crypto token or ticker symbol with a dollar sign ($) in front now links to pricing graphs for those symbols. Cointelegraph found 30 of the top 50 tokens by market …
Adoption / Jan. 16, 2023
Twitter down the same day Jack Dorsey launches decentralized alternative
Twitter suffered another outage on March 1 as thousands of users flagged issues with Elon Musk’s social media platform. The outage took place as Twitter founder Jack Dorsey’s new project, Bluesky, went into beta testing. Data from Downdetector showed thousands of issue reports from Twitter users from 9 am UTC, with issues slowly being resolved over a five hour period. 59% of the reported problems were from mobile app users while a further 35% of issues were flagged by website users. Twitter is yet to issue any updates on the cause of the outage, but various reports indicate that users …
Technology / March 1, 2023