4 ms·
Twitter employees were duped by social engineering. Hacker gained access to their credentials, used them to get access to internal Twitter tools that allowed th
by devalgo 6y ago
Twitter employees were duped by social engineering. Hacker gained access to their credentials, used them to get access to internal Twitter tools that allowed them to takeover Accounts. Not very sophisticated but still alarming that random Twitter employees have access to this kind of tool and don't have better internal account security.
- deleted 6y ago[deleted]
- the-pigeon 6y agoAre you just guessing? I don't see anyone reporting this. I also highly doubt normal Twitter employees can impersonate any users. I would seriously hope it's less than 100 people with the DB or server access necessary to tweet as someone they don't have auth credentials for.
- devalgo 6y agoI believe Twitter themselves reported that. Edit: "We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools." https://twitter.com/TwitterSupport/status/1283591846464233474 https://twitter.com/TwitterSupport/status/128359184646423347...
- eternalban 6y ago> Not very sophisticated They did not apply social engineering to a random set of Twitter employees. Simply identifying this select subset of employees indicates sophistication.
- devalgo 6y agoMy point was more that they didn't need to have access to some 0 day exploit to do this. There's been a lot of "conspiracy" type talk online that this was actually a 3 letter agency showing off their Twitter backdoor.