Twitter suffered a major breach in which attackers hijacked prominent accounts including those of Barack Obama, Joe Biden, Elon Musk, Bill Gates, and Jeff Bezos and used them to post a Bitcoin-doubling scam. The fraudulent messages urged followers to send cryptocurrency to attacker-controlled wallets, exploiting the credibility and reach of the compromised accounts to amplify the fraud.
Twitter said the intrusion stemmed from a social engineering attack against employees that gave the attackers access to internal administrative tools, while reports also raised the possibility that an insider may have been paid or otherwise assisted. In response, the company locked affected accounts and temporarily restricted all verified accounts from posting until it could restore access safely and contain the incident.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Twitter said the incident was caused by a social engineering attack against its employees that leveraged internal administrative tools. The company also investigated whether an employee directly hijacked the accounts or provided attackers access to the internal tool.
During the breach response, Twitter temporarily locked the compromised accounts and also restricted all verified accounts in an unprecedented step. The company said access would be restored only when it could do so securely, and later began restoring tweeting functionality to affected accounts.
On 2020-07-16, attackers took over numerous prominent Twitter accounts, including those of Barack Obama, Joe Biden, Elon Musk, Bill Gates, and Jeff Bezos, and used them to post Bitcoin-doubling scam messages. One of the first suspicious tweets was sent from Elon Musk’s account, directing victims to attacker-controlled cryptocurrency addresses.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.