By Zen Soo

Updated 4:51 pm ET

A breach in Twitter's security that allowed hackers to break into the accounts of leaders and technology moguls is one of the worst attacks in recent years and may shake trust in a platform politicians and CEOs use to communicate with the public, experts said Thursday.

The FBI said Thursday it is investigating the hacks, and said the high-profile accounts "appear to have been compromised in order to perpetuate cryptocurrency fraud."

The ruse discovered Wednesday included bogus tweets from former President Barack Obama, Democratic presidential front-runner Joe Biden, Mike Bloomberg and a number of tech billionaires including Amazon CEO Jeff Bezos, Microsoft co-founder Bill Gates and Tesla CEO Elon Musk. Celebrities Kanye West and his wife, Kim Kardashian West, were also hacked.

Twitter said the hackers used "social engineering" to target some of the company's employees and then gained access to the accounts. The term refers to taking advantage of human nature via phishing attacks, tricking people into downloading malicious software or compromising them by offering something in return for information. Twitter did not say how its employees were compromised.

The attackers sent out tweets from the accounts of the public figures, offering to send $2,000 for every $1,000 sent to an anonymous Bitcoin address.

Cybersecurity experts say such a breach could have dire consequences since the attackers were tweeting from verified, globally influential accounts with millions of followers.

"If you receive a tweet from a verified account, belonging to a well-known and therefore trusted person, you can no longer assume it's really from them," said Michael Gazeley, managing director of cybersecurity firm Network Box.

Reacting to the breach, Twitter swiftly deleted the tweets and locked down the accounts to investigate. In the process it prevented verified users from sending out tweets for several hours.

The company said Thursday it has taken "significant steps to limit access to internal systems and tools." User passwords did not appear to have been compromised, Twitter said, so it's not necessary for users to reset them.

Many celebrities, politicians, and business leaders often use Twitter as a public platform to make statements. U.S. President Donald Trump, for example, regularly uses Twitter to post about national and geopolitical matters, and his account is closely followed by media, analysts and governments around the world. The White House said Thursday his account was secure and wasn't jeopardized by the hacks.

Twitter faces an uphill battle in regaining people's confidence, Gazeley said. For a start, it needs to figure out exactly which accounts were hacked and show the vulnerabilities have been fixed, he said.

"If key employees at Twitter were tricked, that's actually a serious cybersecurity problem in itself," he said. "How can one of the world's most used social media platforms have such weak security, from a human perspective?"

Rachel Tobac, CEO of Socialproof Security, said that the breach appeared to be largely financially motivated. But such an attack could cause more serious consequences.

"Can you imagine if they had taken over a world leader's account, and tweeted out a threat of violence to another country's leader?" asked Tobac, a social engineering hacker who specializes in providing training for companies to protect themselves from such breaches.

Tobac said companies can guard themselves against such attacks by beefing up multi-factor authentication — where users have to present multiple pieces of evidence as authentication before being allowed to log into a system.

Such a process could include having a physical token that an employee must have with them, on top of a password, before they can log into a corporate or other private system. Other methods include installing technical tools to monitor for suspicious insider activities and reducing the number of people who have access to sensitive data, Tobac said.

This week's case follows last year's federal investigation of two former Twitter employees charged with spying on users for the Saudi government.

Several U.S. lawmakers called on Twitter to cooperate with authorities including the Department of Justice and the FBI to secure the site after the latest breach.

"I am concerned that this event may represent not merely a coordinated set of separate hacking incidents but rather a successful attack on the security of Twitter itself," said Sen. Josh Hawley, a Missouri Republican.

He added that millions of users relied on Twitter not just to send tweets but also to communicate privately via direct messaging. Twitter hasn't said if hackers were able to access the private messages of their high-profile targets.

Oregon Democratic Sen. Ron Wyden said Twitter CEO Jack Dorsey told him in a private conversation in 2018 that the company was working on protecting direct messages, known as DMs, with end-to-end encryption.

But that promise never materialized, Wyden said Thursday, leaving everyone's private messages "vulnerable to employees who abuse their internal access to the company's systems, and hackers who gain unauthorized access."

"This is a vulnerability that has lasted for far too long, and one that is not present in other, competing platforms," Wyden said in an emailed statement. "If hackers gained access to users' DMs, this breach could have a breathtaking impact, for years to come."

___

AP reporters Matt O'Brien in Providence, Rhode Island, Eric Tucker, and Kevin Freking in Washington and Barbara Ortutay in Oakland, California contributed to this report.

Share:
More In Business
‘Chainsaw Man’ anime film topples Springsteen biopic at the box office
A big-screen adaptation of the anime “Chainsaw Man” has topped the North American box office, beating a Springsteen biopic and “Black Phone 2.” The movie earned $17.25 million in the U.S. and Canada this weekend. “Black Phone 2” fell to second place with $13 million. Two new releases, the rom-com “Regretting You” and “Springsteen — Deliver Me From Nowhere,” earned $12.85 million and $9.1 million, respectively. “Chainsaw Man – The Movie: Reze Arc” is based on the manga series about a demon hunter. It's another win for Sony-owned Crunchyroll, which also released a “Demon Slayer” film last month that debuted to a record $70 million.
Flights to LAX halted due to air traffic controller shortage
The Federal Aviation Administration says flights departing for Los Angeles International Airport were halted briefly due to a staffing shortage at a Southern California air traffic facility. The FAA issued a temporary ground stop at one of the world’s busiest airports on Sunday morning soon after U.S. Transportation Secretary Sean Duffy predicted that travelers would see more flights delayed as the nation’s air traffic controllers work without pay during the federal government shutdown. The hold on planes taking off for LAX lasted an hour and 45 minutes and didn't appear to cause continued problems. The FAA said staffing shortages also delayed planes headed to Washington, Chicago and Newark, New Jersey on Sunday.
Boeing defense workers on strike in the Midwest turn down latest offer
Boeing workers at three Midwest plants where military aircraft and weapons are developed have voted to reject the company’s latest contract offer and to continue a strike that started almost three months ago. The strike by about 3,200 machinists at the plants in the Missouri cities of St. Louis and St. Charles, and in Mascoutah, Illinois, is smaller in scale than a walkout last year by 33,000 Boeing workers who assemble commercial jetliners. The president of the International Association of Machinists says Sunday's outcome shows Boeing hasn't adequately addressed wages and retirement benefits. Boeing says Sunday's vote was close with 51% of union members opposing the revised offer.
FBI’s NBA probe puts sports betting businesses in the spotlight
The stunning indictment that led to the arrest of more than 30 people — including Miami Heat guard Terry Rozier and other NBA figures — has drawn new scrutiny of the booming business of sports betting in the U.S. The multibillion-dollar industry has made it easy for sports fans — and even some players — to wager on everything from the outcome of games to that of a single play with just a few taps of a cellphone. But regulating the rapidly-growing industry has proven to be a challenge. Professional sports leagues’ own role in promoting gambling has also raised eyebrows.
Tesla’s profit fell in third quarter even as sales rose
Tesla, the car company run by Elon Musk, reported Wednesday that it sold more vehicles in the past three months after boycotts hit hard earlier this year, but profits still fell sharply. Third-quarter earnings fell to $1.4 billion, from $2.2 billion a year earlier. Excluding charges, per share profit of 50 cents came in below analysts' estimate. Tesla shares fell 3.5% in after-hours trading. Musk said the company's robotaxi service, which is available in Austin, Texas, and San Francisco, will roll out to as many as 10 other metro areas by the end of the year.
Load More