More than 1,000 people at Twitter had ability to aid hack of accounts

More than 1,000 people at Twitter had ability to aid hack of accounts
PHOTO: Reuters

SAN FRANCISCO - More than a thousand Twitter employees and contractors as of earlier this year had access to internal tools that could change user account settings and hand control to others, two former employees said, making it hard to defend against the hacking that occurred last week.

Twitter Inc and the FBI are investigating the breach that allowed hackers to repeatedly tweet from verified accounts of the likes of Democratic presidential candidate Joe Biden, billionaire philanthropist Bill Gates, Tesla Chief Executive Elon Musk and former New York Mayor Mike Bloomberg.

Twitter said on Saturday that the perpetrators "manipulated a small number of employees and used their credentials" to log into tools and turn over access to 45 accounts. On Wednesday, it said that the hackers could have read direct messages to and from 36 accounts but did not identify the affected users.

The former employees familiar with Twitter security practices said that too many people could have done the same thing, more than 1,000 as of earlier in 2020, including some at contractors like Cognizant.

Twitter declined to comment on that figure and would not say whether the number declined before the hack or since. The company was looking for a new security head, working to better secure its systems and training employees on resisting tricks from outsiders, Twitter said.

Cognizant did not respond to a request for comment.

"That sounds like there are too many people with access," said Edward Amoroso, former chief security officer at AT&T.

Responsibilities among the staff should have been split up, with access rights limited to those responsibilities and more than one person required to agree to make the most sensitive account changes. "In order to do cybersecurity right, you can't forget the boring stuff."

Threats from insiders, especially lower-paid outside support staff, are a constant worry for companies serving large numbers of users, cybersecurity experts said. They said that the greater the number of people who can change key settings, the stronger oversight must be.

Stumbles

The former employees said that Twitter had gotten better about logging the activity of its people in the wake of previous stumbles, including searches of records by an employee accused last November of spying for the government of Saudi Arabia.

But while logging helps with investigations, only alarms or constant reviews can turn logs into something that can prevent breaches.

Former Cisco Systems Chief Security Officer John Stewart said companies with broad access need to adopt a long series of mitigations and "ultimately ensuring that the most powerful authorised people are only doing what they are supposed to be doing."

Who exactly pulled off the hacking spree isn't clear, but outside researchers such as Allison Nixon of Unit 221B say the incident appears linked to a cluster of cybercriminals who regularly traded in novelty handles - especially rare one-or-two character account names - that are treated a bit like the vanity license plates of the online world.

Although the public evidence tying the hacking to those was circumstantial, ultra-short Twitter handles were among the first to be hijacked.

In addition, the forums where those hackers were active have long been replete with boasts about having access to Twitter insiders, according to Nixon and Nick Bax, an analyst with StopSIMCrime, a group that lobbies for greater protection against "SIM swapping" - a phone number hijacking technique often used by these kinds of hackers.

Bax said he had seen reference on forums to "Twitter plugs" or "Twitter reps" - the terms used to describe cooperative Twitter employees - since as far back as 2017.

The potential involvement of low-level cybercriminals has particularly alarmed professionals because of the implication that a hostile government might be able to cause even greater havoc.

Access to accounts for national leaders was limited to a much smaller number of people after a rogue employee briefly deleted President Donald Trump's account two years ago. That could explain why Biden's account was hijacked but not Trump's.

Twitter should expand the number of protected accounts, said former Twitter security engineer John Adams. Among other things, accounts with more than 10,000 followers should at least need two people to change key settings.

Security experts said they were worried that Twitter has too much work to do and too little time before the campaign for the Nov. 3 US election intensifies, with potential inference domestically and from other countries.

Said Ron Gula, a cybersecurity investor who co-founded network security company Tenable, "The question really is: Does Twitter do enough to prevent account takeovers for our presidential candidates and news outlets when faced with sophisticated threats that leverage whole-of-nation approaches?"

On a call to discuss company earnings on Thursday, Twitter Chief Executive Jack Dorsey acknowledged past missteps.

"We fell behind, both in our protections against social engineering of our employees and restrictions on our internal tools," Dorsey told investors.

homepage

trending

trending
    'I'm doing all this from my heart': Senior volunteer on his love of helping the community for almost 30 years
    Ruby Lin strikes touristy Merlion pose in Singapore at Vivian Hsu's 'recommendation'
    Bishan bak kut teh stall owner died of overwork trying to repay $100k debt, says wife
    A taste of home: Burmese friends open cafe in Bras Basah selling authentic Myanmar cuisine
    Mum of 6 who juggles 3 jobs starts free breakfast club for children in Ang Mo Kio
    Gossip mill: Liu Wai Hung to open entertainment complex in Malaysia, officials indicted in late Lee Sun-kyun case, Hong Kong actor with cancer performs to pay bills
    Operator of F&B chain Ayam Penyet President fined $1,000 after SFA finds food safety lapses at Hillion Mall outlet
    'You worried about us too much': Tay Ying has heart-to-heart talk with mum Hong Huifang before marriage
    Malaysian govt-owned land in Marsiling? Residents express surprise at land acquisition for Woodlands Checkpoint extension
    Singapore-registered supercars' owners fined for parking illegally in Thailand
    Ayden Sng sells his 'go-to' drink Milo Dinosaur in China cafe for reality show Smile at You
    Kia Carnival Hybrid review: Hybrid power and modern updates for a spacious family MPV

Singapore

Singapore
    • 'I suppose this will be my life': Geylang resident dismayed as neighbour blasts music past midnight
    • From cash and gold to leaves: 3 women, 1 man charged over suspected involvement in spiritual 'blessing' scams
    • 'A transitional phase': Food security expert not worried by drop in local production of vegetables and seafood
    • Barge grounded off Tanjong Beach; no reports of damage, injuries
    • Over 20,000 devotees attend Sri Sivan Temple consecration, crowd almost breaks through barricades
    • 40 Singaporeans going on 'Single's Inferno' trips to Japan to find love, minus the cameras
    • Cyclist sent to hospital after accident with police vehicle along Keppel Road
    • Former senior minister Teo Chee Hean to take over from Lim Boon Heng as Temasek chairman
    • Man taken to hospital after fight with stepfather in Yishun, furniture damaged in brawl
    • Wrong food delivery: Man 'feels unsafe', calls police

Entertainment

Entertainment
    • Hazelle Teo announces engagement to pianist James Wong
    • E-Junkies: Katy Kung agreed to do tough labour in TVB reality show because 'might as well choose the most challenging one'
    • Half-Singaporean Katseye member Megan comes out as bisexual during livestream
    • 'I was totally fooled': Behind-the-scenes footage of Lee Jun-hyuk's ad tickles netizens
    • Zawe Ashton and fiancé Tom Hiddleston expecting second child
    • Jared Leto facing allegations from 9 women of inappropriate behaviour
    • Rita Ora celebrates her 'sexuality' in new single Heat
    • Pedro Pascal finds it scary joining the MCU
    • Sean 'Diddy' Combs warned to stop 'nodding' in the direction of jury during his sex trafficking trial
    • Dakota Johnson admits sending gorilla poop to a friend's ex

Lifestyle

Lifestyle
    • Pamper yourself on your next shopping trip with these exclusive deals
    • Unable to bear children, she proposed annulment of marriage so he could start a family. He chose love
    • The taller, the better? Tinder's new height filter trial is dividing opinion
    • New French restaurant concept by Zouk Group to open in Bugis
    • Warning: These World Chocolate Day destinations might melt your heart (and tastebuds)
    • Today's norms, tomorrow's 'you did what?!' moments - 60 Singapore things we'll one day have to explain
    • Land Rover Defender lineup gets facelift
    • Top picks for Father's Day 2025 in Singapore: Best restaurants, experiences and gifts
    • Touring Onan Road, a freehold landed estate with 'hidden' enclave of shophouses
    • From 'playgrounds' to 'playscapes': Punggol sees new play areas with giant pencils, kinetic bugs and a 'crocodile'

Digicult

Digicult
    • Slim, sleek, but slightly too short-lived: Samsung Galaxy S25 Edge review
    • World's best Dota 2 teams to compete for $1m prize pool in Singapore in November
    • A $500 wake-up call: How the Samsung Galaxy Ring made me realise my stress
    • Monster Hunter Wilds producer explains how game has remained unique and fresh over 20 years
    • Initiative by IMDA, AI Verify Foundation tests AI accuracy, trustworthiness in real-world scenarios
    • Under siege? Helldivers 2's latest city to be invaded by aliens could be spoof of Singapore
    • Honor 400 Series launches in Singapore with first free in-device AI image-to-video tool
    • Home Team humanoid robots to be deployed by mid-2027, $100m to be invested: Josephine Teo
    • Ado concert review: Singer without a face ignites fans while in cage with only silhouette visible
    • EU and US authorities take down malware network

Money

Money
    • Wall Street equity indexes close higher after US-China tariff truce
    • Giant deal: Malaysian company to acquire Cold Storage and Giant supermarket chains in Singapore
    • Best credit card promotions in Singapore (June 2025): Citibank, DBS, HSBC, UOB and more
    • The biggest misconceptions about buying property in Singapore's CCR in 2025
    • 9 best personal loans in Singapore with lowest interest rates (June 2025)
    • Best fixed deposit rates in Singapore (June 2025): Minimum deposits from $500, rates up to 2.45%
    • SG60 Baby Gift: What to expect if you're expecting
    • The surprising reasons some Singaporean buyers are choosing smaller condo units (even when they can afford more)
    • 'Thank you for your hard work': Scoot gives 4.91 months of bonus, shares on TikTok
    • US House plans quick action on Trump cuts to foreign aid spending

Latest

Latest
  • WorldPride parade-goers march through Washington in defiance of Trump
  • Protesters rally against immigration agents for second day in Los Angeles
  • Proud Boys leaders seek $128 million over Jan 6 prosecutions
  • Tens of thousands march in Romania demanding LGBTQ equality
  • Ukraine denies postponing prisoner swaps as Russian strike on Kharkiv kills 4
  • Thailand and Cambodia reinforcing troops on disputed border after May skirmish, Thai minister says
  • Iran says US travel ban shows 'deep hostility' for Iranians, Muslims
  • Dismay and disbelief as Trump bans visitors from a dozen countries
  • Bangladesh to hold election in first half of April 2026, interim PM says

In Case You Missed It

In Case You Missed It
  • Government official impersonation scam: Syndicate received gold bars worth $500k, cash from victims
  • Queues at VEP application centres in Singapore, JB after news of enforcement from July 1
  • Malaysian woman apologises to 11-year-old daughter for 'only' spending $300k on her birthday
  • Boy, 4, caught smoking under a Bangkok bridge sent to government-run shelter
  • 'I feel incredibly honoured': Drum major who dreamed of role as teen leads Singapore Police Force Band in centennial celebration
  • Over 170 travellers nabbed for evading GST, smuggling large sums of cash in island-wide operation
  • Enforcement officer lays tape measure on road to assess illegal parking, impresses netizens
  • Woman crawls out of storm drain in shocking Manila street scene
  • DBS staff, police stop 2 victims from losing $820k to government official impersonation scams
This website is best viewed using the latest versions of web browsers.