Attackers compromised Twitter employee access through a coordinated social engineering campaign and used the company’s internal account-management tools to seize control of numerous high-profile accounts, including those of Barack Obama, Joe Biden, Bill Gates, Elon Musk, Jeff Bezos, Apple, Uber, and Warren Buffett. The hijacked accounts posted fraudulent messages promising to double any bitcoin sent to an attacker-controlled wallet, which collected more than $100,000 in cryptocurrency within hours. Twitter removed the tweets, locked affected accounts, and temporarily restricted posting and other functions for verified users as it investigated whether additional data, including direct messages or other account information, had been accessed.
Reporting indicated the attackers may initially have been focused on hijacking coveted “OG” usernames and may have ties to the OGUsers gray-market forum, where access to Twitter accounts was allegedly advertised before the breach. Twitter said about 130 accounts were targeted, though only a smaller subset was fully controlled, and the incident raised broader concerns because the platform is used by political leaders, major corporations, and financial markets; the FBI opened an investigation, lawmakers sought briefings, and Twitter shares fell in after-hours trading as the company worked to contain what was described as one of the most serious security failures in its history.

Get the infrastructure and lures behind it.
12 events from the most recent confirmed update back to the earliest known activity.
Joseph James O’Connor, known as PlugwalkJoe, pleaded guilty in New York to charges tied to the July 2020 Twitter breach after being extradited from Spain. Prosecutors said he participated in the takeover of more than 130 high-profile accounts and related cybercrime, including fraud, extortion, and money laundering offenses.
Federal and state authorities announced charges against three alleged participants in the July 2020 Twitter breach, including the arrest of a 17-year-old in Florida identified as the alleged mastermind. The case involved the FBI, IRS Criminal Investigation, Secret Service, and Justice Department, marking a major law-enforcement action following the incident.
In an update on its investigation, Twitter disclosed that attackers used its internal tools to download account data from eight unverified users during the July 2020 breach. The company also said 130 accounts were targeted and 45 were successfully used to tweet as part of the scam.
Subsequent reporting tied the operation to actors active on OGUsers and identified a suspected participant as a 21-year-old student previously linked to SIM-swapping and the 2019 compromise of Jack Dorsey's Twitter account. This added early attribution detail to how the attack may have been organized.
Following the breach, the Senate Intelligence Committee requested a briefing as lawmakers and analysts raised concerns about the national security and election-related risks exposed by the compromise. The incident highlighted the danger of unauthorized access to accounts used by major political and business figures.
The FBI opened an investigation into the account takeover campaign, and its San Francisco field office warned the public not to send cryptocurrency connected to the scam. The incident quickly drew broader scrutiny because of the prominence of the affected accounts.
Reporting on the incident indicated the attackers used Twitter's internal account-management or "admin" tools to seize control of accounts and post the scam messages. Some reports also suggested an insider may have been bribed or otherwise abused access to those tools.
Twitter stated that the breach appeared to result from a coordinated social engineering attack against employees with access to internal systems and tools. The company said about 130 accounts were affected, with attackers gaining control of only a smaller subset.
As it responded to the incident, Twitter locked affected accounts, deleted the scam tweets, and temporarily limited tweeting and some account functions for verified users. The company said it was investigating the breach while trying to contain further abuse.
Within hours of the takeover, the cryptocurrency wallet promoted in the fraudulent tweets received more than $100,000 in bitcoin through hundreds of transactions. Reports noted roughly 12.9 BTC had been sent to the wallet, though some transfers may have been intended to make the scam appear legitimate.
On July 15, attackers hijacked numerous prominent Twitter accounts, including those of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Jeff Bezos, Apple, Uber, and others. The compromised accounts posted Bitcoin-doubling scam messages, indicating a platform-level breach rather than isolated account takeovers.
In the days before the breach, a user on the OGUsers gray-market forum reportedly offered direct access to Twitter accounts for $2,000 to $3,000 each. Early activity appears to have focused on hijacking rare "OG" usernames before shifting to a broader scam.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
16 references tracked. Mallory keeps watching after this page renders.
theguardian.com
Open sourcenytimes.com
Open sourcetheverge.com
Open sourcetheverge.com
Open sourcebusinessinsider.com
Open sourcetechcrunch.com
Open sourcecnn.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.