Twitter Investigation About Bitcoin Theft: Two-Factor Authentication Bypassed!

FL
Foley & Lardner

Contributor

Foley & Lardner LLP looks beyond the law to focus on the constantly evolving demands facing our clients and their industries. With over 1,100 lawyers in 24 offices across the United States, Mexico, Europe and Asia, Foley approaches client service by first understanding our clients’ priorities, objectives and challenges. We work hard to understand our clients’ issues and forge long-term relationships with them to help achieve successful outcomes and solve their legal issues through practical business advice and cutting-edge legal insight. Our clients view us as trusted business advisors because we understand that great legal service is only valuable if it is relevant, practical and beneficial to their businesses.
With 45 of the accounts, the attackers were able to reset the passwords, log into the accounts, and send out tweets — all without alerting the account owners until after the fact.
United States Technology

Darkreading.com reported that "Twitter said its investigations so far showed that someone used social engineering to obtain credentials belonging to a small number of employees and then used those credentials to somehow bypass two-factor protections and access a key internal system."  The July 20, 2020 article entitled "Twitter Breach Highlights Privileged Account Security Issue" included these comments:

The attackers used their access to target 130 Twitter accounts, including several belonging to high-profile individuals such as Democratic presidential hopeful Joe Biden, former president Barack Obama, and business leaders including Bill Gates, Jeff Bezos, and Elon Musk. 

With 45 of the accounts, the attackers were able to reset the passwords, log into the accounts, and send out tweets — all without alerting the account owners until after the fact.

The tweets urged users to send Bitcoin to an address contained in the message within a specific period and get double the amount in return.

The Twitter attack has raised considerable concern, including among US lawmakers, because of just how influential the platform has become in recent years.

Politicians, activists, and numerous others from around the world use Twitter widely for everything from making policy announcements and communicating business and trade decisions to expressing opinions and garnering support for various cause.

Many have said the attackers could easily have used their access to create substantial havoc by tweeting misleading information on behalf of some of the most influential people on the platform.

Maybe two-factor authentication is insufficient, what do you think?

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More