First reportedJuly 15, 2020
ActivityJuly 15, 2020
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Twitter users and account holders (including verified accounts)
  • Victims who sent cryptocurrency to scam addresses
  • Twitter, Inc.

Initial access

  • phishing
  • stolen_creds

Impact

  • financial_loss
  • data_theft

Attribution

unknown low confidence

Cited sources describe social engineering and internal tool abuse; actor identity is not asserted here from the included sources.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1566: NYDFS described a social engineering/phishing component used to obtain access to internal systems.
  • T1078: Attackers used compromised access to internal tools to control accounts, consistent with abuse of valid accounts/privileged access.

Mitigations

Now

  • Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.

Soon

  • Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.

Later

  • Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.

Detection ideas

Alert on anomalous authentication patterns

Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.

Data sources: IdP sign-in logs, SSO audit logs, VPN authentication logs

Detect risky account recovery and MFA changes

Alert when MFA factors are reset/added, recovery email/phone is changed, or helpdesk performs high-risk password resets outside normal hours.

Data sources: IdP audit logs, Helpdesk/ticketing logs

Sources

Twitter internal tool compromise leads to takeover of verified accounts for crypto scam · Baitaphish