Twitter said attackers used social engineering against employees to gain access to internal tools, then targeted 130 accounts and successfully reset passwords, logged in to, and tweeted from 45 of them as part of a high-profile bitcoin scam. The takeover hit prominent accounts including those of Barack Obama, Joe Biden, Bill Gates, Jeff Bezos, Elon Musk, and Kanye West, while the company later disclosed that attackers also downloaded account data from eight users whose accounts were not verified.
Twitter later confirmed the attackers accessed the direct-message inboxes of up to 36 targeted accounts, including one elected official in the Netherlands, reportedly Geert Wilders, though it said it had no evidence other current or former elected officials were similarly affected. As the FBI investigated and lawmakers pressed for answers, Coinbase said it blocked roughly 1,100 customers from sending funds to the scam wallet addresses, preventing more than $280,000 in bitcoin transfers, although about 14 users still sent roughly $3,000 before the blacklist took effect.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Twitter disclosed that the July 15 account takeover began with a phone spear-phishing attack against a small number of employees. After initial stolen credentials did not grant access to account-support tools, the attackers targeted additional staff and ultimately reached Twitter's internal administrative systems.
The FBI confirmed it was investigating the Twitter hack, while lawmakers called for inquiries into Twitter and the circumstances of the breach. These responses reflected escalating concern over the compromise of prominent accounts and private communications.
Twitter said attackers accessed the direct message inboxes of up to 36 of the 130 targeted accounts. The company also confirmed that one elected official in the Netherlands was among those affected in this way.
Coinbase said it blacklisted wallet addresses tied to the Twitter scam and stopped roughly 1,100 customers from sending funds, preventing more than $280,000 in bitcoin transactions. About 14 Coinbase users still sent around $3,000 before the blacklist took effect.
Twitter disclosed that attackers downloaded account data from eight users during the intrusion, and said none of those accounts were verified. This detail was included in the company's public updates as it continued investigating the breach.
In July 2020, attackers used social engineering against Twitter employees to gain access to internal tools and target 130 high-profile accounts. They successfully reset passwords, logged into 45 accounts, and used many of them to post bitcoin scam messages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
arstechnica.com
Open sourceengadget.com
Open sourcetheverge.com
Open sourcecnn.com
Open sourceblog.twitter.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.