Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

SEC Developing Framework for Tokenized Securities Trading Under ‘Innovation Without Arbitrage’ Principle

June 8, 2026

Monad jumps 10% – THIS could decide MON’s next move

June 8, 2026

RWA Sector Grows Quietly as Holders Rise Across Plume and Solana

June 8, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Twitter Confirms Spear Phishing Attack Caused Account Takeover
Twitter Confirms Spear Phishing Attack Caused Account Takeover
Security and Privacy

Twitter Confirms Spear Phishing Attack Caused Account Takeover

July 24, 2023No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Twitter has confirmed that the social engineering attack which enabled the takeover of major accounts was achieved by a spear-phishing attack.

In an update to its previous statement, Twitter said the attack occurred on July 15 and “targeted a small number of employees through a phone spear-phishing attack.” This attack enabled the attackers to obtain access to both the internal network and specific employee credentials that granted them access to internal support tools.

“Not all of the employees that were initially targeted had permissions to use account management tools, but the attackers used their credentials to access our internal systems and gain information about our processes,” it said. This then enabled them to target additional employees who had access to account support tools.

Using the credentials of the employees with access to these tools, the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36 and downloading the Twitter data of seven. 

In the initial attack, Twitter said on 16 July that the coordinated account hijacking campaign wad done by a “coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.” For a period of time, accounts with millions of followers belonging to Jeff Bezos, Bill Gates, Barack Obama, Joe Biden, Elon Musk, Kanye West and others were briefly hijacked and used to promote a cryptocurrency scam. The corporate accounts of Apple, Bitcoin, Coinbase and others were also taken over.

A day later, Twitter disclosed that 130 accounts were targeted, and the successfully compromised accounts represented a  “small subset” of the total number of accounts the attackers had in their crosshairs.

See also  Defillama Confirms April 2026 as Crypto's Most-Hacked Month With 30 Incidents

Answering questions about access to user accounts, Twitter said it has teams around the world that help with account support that use proprietary tools to help with a variety of support issues. “Access to these tools is strictly limited and is only granted for valid business reasons,” it explained. “We have zero tolerance for misuse of credentials or tools, actively monitor for misuse, regularly audit permissions and take immediate action if anyone accesses account information without a valid business reason.”

However, Twitter said it is now “taking a hard look at how we can make [the access tools] even more sophisticated.”

Looking forward, it said since the attack it has “significantly limited access to our internal tools and systems to ensure ongoing account security while we complete our investigation” and it is continuing to invest in increased security protocols, techniques and mechanisms.

“Going forward, we’re accelerating several of our pre-existing security workstreams and improvements to our tools. We are also improving our methods for detecting and preventing inappropriate access to our internal systems and prioritizing security work across many of our teams. We will continue to organize ongoing company-wide phishing exercises throughout the year.”

Stuart Reed, UK director at Orange Cyberdefense, said: “As suspected, this breach resulted from social engineering – hackers preying on human vulnerabilities. Technical countermeasures against phishing attempts and detecting malicious activities today are much more robust than they have been in the past. The human, on the other hand, is more complex and hard to predict in certain scenarios while easy to manipulate in others.

See also  Preventing the Next Ransomware Attack

“It is vital organizations employ a layered approach of people, process and technology for optimal cybersecurity. This incident underlines the critical importance of awareness and education among employees and the role they play in good data hygiene – cybersecurity is not the sole concern of an individual or a function, it is a shared responsibility of all.”



Source link

Account Attack Caused Confirms Phishing Spear Takeover Twitter
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Bitcoin maximalists say the brutal price crash is just a temporary liquidity crunch caused by the AI boom

June 6, 2026

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

Europe is actively trying to stop the dollar stablecoin takeover

June 1, 2026

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Rarible’s RARI Foundation taps Arbitrum for royalty-embedded EVM chain

December 2, 2023

XRP Lawyer John Deaton Volunteers to Testify Before US Congress

January 5, 2024

Strategy’s STRC stock challenges US Treasuries with higher yield

July 23, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

SEC Developing Framework for Tokenized Securities Trading Under ‘Innovation Without Arbitrage’ Principle

June 8, 2026

Monad jumps 10% – THIS could decide MON’s next move

June 8, 2026

RWA Sector Grows Quietly as Holders Rise Across Plume and Solana

June 8, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$62,460.001.09%
  • ethereumEthereum(ETH)$1,647.342.61%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$592.271.13%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.131.05%
  • solanaSolana(SOL)$65.081.23%
  • tronTRON(TRX)$0.3268190.61%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • HyperliquidHyperliquid(HYPE)$61.042.26%