Twitter internal tool compromise leads to takeover of verified accounts for crypto scam
In July 2020, attackers gained access to Twitter’s internal tools through social engineering and used that access to take over high-profile verified accounts to promote a cryptocurrency scam. Twitter published updates describing the incident and remediation steps, and the New York Department of Financial Services (NYDFS) later issued a detailed report on control failures and recommendations. The incident demonstrated how compromise of internal administration tools can create outsized fraud and reputational damage even without large-scale data theft.
First reported July 15, 2020Fraudmed overall confidence
T1566: NYDFS described a social engineering/phishing component used to obtain access to internal systems.
T1078: Attackers used compromised access to internal tools to control accounts, consistent with abuse of valid accounts/privileged access.
Mitigations
Now
Enforce phishing-resistant MFA for workforce and privileged accountsReduces successful account takeovers from stolen passwords and common social engineering techniques.
Soon
Harden helpdesk and password reset workflowsPrevents attackers from using social engineering to reset MFA or regain access via the identity recovery channel.
Later
Apply conditional access and session risk controls (device posture, geo, impossible travel)Limits account abuse by requiring stronger signals for high-risk sign-ins and reducing lateral access after compromise.
Detection ideas
Alert on anomalous authentication patterns
Flag first-time device logins, new geo/ASN, impossible travel, and sign-ins immediately followed by privilege escalation or access to sensitive apps.