Attackers phoned Twitter employees posing as IT help desk, harvested VPN credentials, and used internal admin tools to hijack 130 high-profile accounts for a "double your bitcoin" scam.
Reviewed by the Social Engineering Examples team.
On July 14-15, 2020, attackers seized control of dozens of the world's most prominent Twitter accounts and used them to post a "double your bitcoin" cryptocurrency scam. Compromised accounts included Barack Obama, Joe Biden, Elon Musk, Jeff Bezos, Bill Gates, Kim Kardashian West, Apple, Uber, and several cryptocurrency companies. For several hours Twitter appeared unable to stop the takeovers, which reached the followers of accounts with tens of millions of subscribers.
The initial access was not a sophisticated technical exploit. According to the New York State Department of Financial Services (DFS) investigation and Twitter's own disclosure, the attackers phoned Twitter employees, claimed to be from Twitter's internal IT help desk, and said they were resolving a problem with the company's VPN. This was highly plausible because Twitter, like many firms, had shifted to remote work during the COVID-19 pandemic and VPN issues were common. Employees were directed to a phishing site mimicking Twitter's internal VPN login. As employees entered credentials, the attackers relayed them into the real Twitter login in real time and captured the resulting multi-factor authentication response, defeating MFA. DFS found the attackers successfully social-engineered four employees; some employees did report the calls to Twitter's fraud team, but at least one provided the credentials the attackers were after.
The first compromised employees lacked access to the sensitive account-management tools, so the attackers used their footholds to move through the network and identify and target employees who did have privileged tool access. With that access they could change email addresses and reset controls on any account. They first took over short, desirable "OG" usernames and sold access to them, then pivoted to verified high-profile accounts to lend credibility to the bitcoin scam. In total, 130 accounts were targeted, passwords were reset on 45, direct messages of 36 were accessed, and Twitter data was downloaded for 7.
Authorities identified suspects within roughly two weeks. On July 31, 2020, the US DOJ announced charges against Mason Sheppard and Nima Fazeli (Northern District of California) and an unnamed juvenile; Florida state prosecutors separately charged 17-year-old Graham Ivan Clark, called the mastermind, with 30 felony counts. IRS-CI traced and de-anonymized the bitcoin transactions to identify hackers. In March 2021 Clark pleaded guilty in Florida state court and agreed to a three-year sentence as a youthful offender.
At an awareness altitude, the attack followed a clear kill chain. Recon: the crew scraped LinkedIn and other public sources to find Twitter employees likely to have internal tool access and to gather personal details and contact numbers. Contact: they cold-called those employees by phone, posing as Twitter's IT help desk. Rapport/pretext: they cited a VPN problem (credible during pandemic remote work) and used the personal details they had collected to sound like a legitimate internal colleague, so the employee trusted them. Exploitation: employees were steered to a look-alike internal VPN login page; captured credentials and the live MFA prompt were passed to the real system fast enough to slip past two-factor protection. Escalation: because the first accounts lacked the needed permissions, the attackers used their access to find and repeat the trick against employees who controlled account-management tools. Payout: with tool access they hijacked accounts and ran a bitcoin-doubling scam. DFS found no evidence any employee knowingly helped; they were manipulated, not complicit.
Pretext: a phone call from "Twitter IT help desk" offering to fix a VPN issue, reinforced with real personal details about the employee. Red flags visible in hindsight: an inbound (not employee-initiated) support call; a request to log in through a link/site provided by the caller rather than the employee's own bookmarked internal portal; pressure to authenticate an MFA prompt the employee did not personally initiate; and the absence of normal out-of-band identity verification, made worse by remote work removing face-to-face confirmation. Notably several employees did sense something was off and reported the calls, showing that reporting culture partially worked even though at least one person was fooled.
Approximately $118,000 in bitcoin stolen from the public; ~$1.5M in ~6,000 further attempted transfers blocked within ~40 minutes by DFS-regulated crypto firms (Coinbase, Square, Gemini, Bitstamp). Twitter contained the incident by severely restricting employee access to internal tools. Three suspects charged (July 31, 2020); Graham Clark pleaded guilty in March 2021 to a three-year juvenile sentence. NY DFS issued a public report (Oct 14, 2020) faulting Twitter for lacking a CISO for the prior seven months and for weak access controls, and called for regulating large social media platforms as systemically important. The reputational damage to Twitter far exceeded the modest dollar theft.
A "$37 billion" platform was brought to its knees by a teenager using no malware, no exploit, and no backdoor, only a phone call and a fake login page. It is the canonical case for why the human layer and privileged internal tooling are the real attack surface, why help-desk / IT impersonation vishing is so effective, and why MFA alone (when phishable and relayable in real time) is not sufficient. It also shows how pandemic remote work expanded the vishing pretext surface (VPN troubles) and removed in-person verification.
Phishing-resistant MFA (FIDO2 / hardware security keys) that cannot be relayed by an adversary-in-the-middle; out-of-band verification of any inbound IT support call through a known internal channel before authenticating; strict least-privilege and just-in-time access to sensitive admin tools with additional step-up controls and monitoring; employee training to treat unsolicited support calls and caller-provided login links as suspect and to report them (the reporting some employees did was a partial control); a staffed security leadership function (Twitter had no CISO); and heightened compensating controls for remote-work VPN access.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims, telling them their…
The CEO of a UK energy firm was tricked into wiring €220,000 (~$243,000) to a Hungarian account in March 2019…
Two Scottish small businesses, an unnamed Perth firm in 2019 and Dumfries-based Handmade Craft House in 2026, lost £31,000 and…