Twitter’s website was briefly hijacked after attackers using the name “Iranian Cyber Army” compromised the company’s DNS records and redirected visitors to a black defacement page carrying political messages, an Iranian flag, and contact details. The outage lasted about an hour, and users attempting to reach Twitter.com were sent to the spoofed page instead of the service.
Reporting indicated the redirection was carried out with a valid Twitter username and password, suggesting the incident stemmed from compromised internal credentials rather than a vulnerability at DNS provider Dyn. Twitter said the DNS issue was fixed quickly and that its API and platform applications continued operating during the disruption, while the attack drew added attention because of Twitter’s role in communications around Iran’s disputed election protests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
By about 7:40 a.m. on 2009-12-18, Twitter said the DNS issue had been fixed and service to Twitter.com was restored. The company stated that its DNS records had been temporarily compromised and said it would provide more details after further investigation.
Around 10 p.m. on 2009-12-17, attackers used valid Twitter credentials to alter the company's DNS records, taking Twitter.com offline for about an hour and redirecting visitors to a page claiming responsibility as the 'Iranian Cyber Army.' The defacement displayed political messaging and an Iranian flag, while Twitter's API and applications reportedly continued to function.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
itpro.com
Open sourcewired.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.