Skip to main content
All lessons
Lesson 3Social Engineering Defense pathway

Case Study: The Twitter Phone Phish

One phone call, 130 hijacked accounts

Highlighted wordsare glossary terms — tap one for a plain-language definition.

On July 15, 2020, attackers took over the Twitter accounts of Barack Obama, Elon Musk, Jeff Bezos, Kim Kardashian West, Apple, Uber and several cryptocurrency exchanges and posted a "double your bitcoin" scam. They didn't break any . They phoned Twitter employees, pretended to be the company's own IT help desk, and walked them onto a fake login page. New York's Department of Financial Services investigated and called the attack "unsophisticated" — which is exactly why it is worth studying. [1, 2]

What actually happened

The attackers called Twitter staff claiming to be from the internal help desk, saying they were fixing problems that were common while everyone worked from home. They asked each employee to log in at a site that looked like Twitter's real VPN page — and, because Twitter used one-time codes, they asked for the code too and entered it on the genuine page within seconds. Investigators found roughly 24 hours passed between the first calls and the hijacked tweets. With internal support tools, the group targeted 130 accounts, reset the passwords of 45 of them, and posted the scam. [1, 2]

  • A caller who knows internal jargon and a current company problem is not thereby proved to be an insider.
  • A typed one-time code can be relayed by an attacker in real time — it is not phishing-resistant.
  • Attacks travel fast: the whole event ran its course in about a day.

The impact

Consumers sent more than $118,000 worth of bitcoin to the scam addresses in a few hours. The damage went further than money: the attackers could read direct messages, and regulators pointed out that the same access, days before an election, could have moved markets or spread false announcements from the accounts of world leaders. Investigators also noted Twitter had no chief information security officer at the time. Prosecutors later charged three people, including a teenager, for their alleged roles. [1, 2, 3]

  • The theft was small next to the potential for market and election manipulation.
  • exposes private messages, not just public posts.
  • You do not need elite skills to cause this scale of harm — which means the defense has to be ordinary habits, not genius.

How the response limited the damage

Twitter locked all verified accounts, blocked tweeting, and pulled employee access to the internal tools while it investigated — a blunt move that stopped the scam mid-flight. Regulated cryptocurrency companies including Coinbase, Square, Gemini and Bitstamp blocklisted the scam bitcoin addresses within minutes to hours, preventing a further several hundred thousand dollars in attempted transfers. The lesson: a fast, deliberately over-broad containment step beats a careful one that arrives tomorrow. [1]

  • Containment first: cut access, then investigate.
  • Blocking the payment path is often the fastest way to stop losses.
  • Have a plan written before the day you need it — see the Security incident plan lesson.

What this means for you

Everything that failed here has a personal equivalent. Nobody legitimate — not your bank, your employer's IT, or a platform's "support" — needs your password or your , and CISA's guidance is to hang up and call back on a number you look up yourself. Where you can, replace typed codes with passkeys or a , which can't be relayed to a fake site. And keep the number of accounts that can reset everything else small. [3, 4]

  • Never read a verification code to a caller, however official they sound.
  • Hang up and dial the number on your card, your bill, or the official app.
  • Move your most important accounts to passkeys or a hardware security key.
  • If you did give something away, change the password, sign out other sessions and reset immediately.

Brought to you by NorthBridge

Unfamiliar term? Open the Digital Safety Glossary