Highlighted wordsare glossary terms — tap one for a plain-language definition.
On July 15, 2020, attackers took over the Twitter accounts of Barack Obama, Elon Musk, Jeff Bezos, Kim Kardashian West, Apple, Uber and several cryptocurrency exchanges and posted a "double your bitcoin" scam. They didn't break any EncryptionWhat it means: Converting information into a protected form that unauthorized people cannot easily read.Example: The storage on your locked phone, unreadable without the passcode.What to do: Turn on device encryption and use a passcode or biometric lock.Important: Encryption won't help if someone learns your account password.What does this mean?. They phoned Twitter employees, pretended to be the company's own IT help desk, and walked them onto a fake login page. New York's Department of Financial Services investigated and called the attack "unsophisticated" — which is exactly why it is worth studying. [1, 2]
What actually happened
The attackers called Twitter staff claiming to be from the internal help desk, saying they were fixing Virtual private networkWhat it means: A service that encrypts internet traffic between a device and the VPN provider. It does not make someone anonymous or protect against every scam.Example: Turning one on before using hotel Wi-Fi.What to do: Pick a reputable paid provider and use it when you're on networks you don't control.Important: Free VPNs often sell your browsing data, and no VPN stops phishing.What does this mean? problems that were common while everyone worked from home. They asked each employee to log in at a site that looked like Twitter's real VPN page — and, because Twitter used one-time codes, they asked for the code too and entered it on the genuine page within seconds. Investigators found roughly 24 hours passed between the first PhishingWhat it means: A deceptive email or message designed to make you click, share information, send money, or give account access.Example: An “unpaid delivery fee” text with a link to a page that looks like the post office.What to do: Don't tap links in unexpected messages — open the company's app or type its address yourself.Important: Real companies never ask for your password or a login code by message.What does this mean? calls and the hijacked tweets. With internal support tools, the group targeted 130 accounts, reset the passwords of 45 of them, and posted the scam. [1, 2]
- A caller who knows internal jargon and a current company problem is not thereby proved to be an insider.
- A typed one-time code can be relayed by an attacker in real time — it is not phishing-resistant.
- Attacks travel fast: the whole event ran its course in about a day.
The impact
Consumers sent more than $118,000 worth of bitcoin to the scam addresses in a few hours. The damage went further than money: the attackers could read direct messages, and regulators pointed out that the same access, days before an election, could have moved markets or spread false announcements from the accounts of world leaders. Investigators also noted Twitter had no chief information security officer at the time. Prosecutors later charged three people, including a teenager, for their alleged roles. [1, 2, 3]
- The theft was small next to the potential for market and election manipulation.
- Account takeoverWhat it means: When someone other than the owner gains control of an account, usually through a stolen or reused password, a phished code, or a SIM swap.Example: Friends receive money requests “from you,” and your email forwarding rules have changed on their own.What to do: From a trusted device, change the password, sign out all sessions, review recovery options, and turn on MFA.Important: Email is the master key — protect it first, because attackers reset everything else through it.What does this mean? exposes private messages, not just public posts.
- You do not need elite skills to cause this scale of harm — which means the defense has to be ordinary habits, not genius.
How the response limited the damage
Twitter locked all verified accounts, blocked tweeting, and pulled employee access to the internal tools while it investigated — a blunt move that stopped the scam mid-flight. Regulated cryptocurrency companies including Coinbase, Square, Gemini and Bitstamp blocklisted the scam bitcoin addresses within minutes to hours, preventing a further several hundred thousand dollars in attempted transfers. The lesson: a fast, deliberately over-broad containment step beats a careful one that arrives tomorrow. [1]
- Containment first: cut access, then investigate.
- Blocking the payment path is often the fastest way to stop losses.
- Have a plan written before the day you need it — see the Security incident plan lesson.
What this means for you
Everything that failed here has a personal equivalent. Nobody legitimate — not your bank, your employer's IT, or a platform's "support" — needs your password or your Verification codeWhat it means: A temporary code used to verify a login or action. Don't provide an unexpected code to an incoming caller or message.Example: “Your verification code is 481920.”What to do: Only enter a code on a page or app you opened yourself.Important: A code you didn't request often means someone has your password — change it from a trusted device.What does this mean?, and CISA's guidance is to hang up and call back on a number you look up yourself. Where you can, replace typed codes with passkeys or a Security keyWhat it means: A physical FIDO-compatible device used to provide strong, phishing-resistant authentication.Example: A small USB or tap-to-approve key you use when signing in.What to do: Register two keys: one for daily use and one kept in a safe place.Important: Among the strongest practical options — no method makes an account impossible to compromise.What does this mean?, which can't be relayed to a fake site. And keep the number of accounts that can reset everything else small. [3, 4]
- Never read a verification code to a caller, however official they sound.
- Hang up and dial the number on your card, your bill, or the official app.
- Move your most important accounts to passkeys or a hardware security key.
- If you did give something away, change the password, sign out other sessions and reset Multifactor authenticationWhat it means: Using more than one type of authentication evidence before an account grants access.Example: Entering your password and then approving the login through an authenticator app.What to do: Turn it on first for your email, financial, social-media, and cloud accounts.Important: Never give an unexpected login code to someone who contacts you.What does this mean? immediately.
Why Hygi. recommends this — the guidance above follows these published sources:
NY Department of Financial Services
DFS Calls for Regulation of Social Media Giants After Twitter Hack Investigation (Oct 14, 2020)(opens in a new tab)Official investigation findings: the attack method, 130 targeted accounts, $118,000 stolen, and the crypto firms' rapid blocklisting.
NYU Program on Corporate Compliance and Enforcement
Superintendent Lacewell Announces Release of the DFS Twitter Hack Report(opens in a new tab)Summary of the report: attackers posed as Twitter's IT department and four employees handed over credentials.
U.S. Department of Justice
Three Individuals Charged For Alleged Roles In Twitter Hack(opens in a new tab)Charges brought against those allegedly responsible, including the compromise of internal Twitter accounts.
CISA
Recognize and Report Phishing (Secure Our World)(opens in a new tab)Why no legitimate contact asks for passwords or codes, and how to verify by calling back yourself.
Brought to you by NorthBridge
Unfamiliar term? Open the Digital Safety Glossary