Case file · AP TWEET 2013

How a hacked AP Twitter account wiped $136 billion off stocks in 3 minutes

Published 2026-09-29 · 5 min read · Missing control: Two-factor login on social accounts

A single false sentence posted from a news agency's Twitter account briefly erased about $136 billion from the value of the S&P 500 on April 23, 2013.[1] This case file covers how the Associated Press lost control of its account, why the market reacted so fast, who was charged, and the one control that would have made a stolen password useless.

What happened

At 12:12 p.m. Eastern on Tuesday, April 23, 2013, AP staff received an email that looked like it came from a colleague. It had the subject line "News" and urged them to read an important article through a link dressed up as a story on a major newspaper's website. The link actually led to a fake page asking them to log in. At 12:29 p.m., AP's information security team warned all staff about it.[3]

A little after 1 p.m., the main @AP Twitter account, followed by millions of people, posted a short report of 2 explosions at the White House and said President Barack Obama had been injured. None of it was true.[1][2]

Markets reacted within seconds. The Dow Jones Industrial Average fell 143.5 points, just under 1%, and the S&P 500 lost about $136.5 billion in value. AP staff quickly said on other channels that the account had been hacked, the White House press secretary told reporters the president was fine, and within about 3 minutes prices began to climb back. Twitter suspended both @AP and a second AP account, @AP_Mobile.[1][2]

How they got in

AP said the hijacking was preceded by phishing attempts against its corporate network.[2] Phishing is an email designed to trick someone into typing a password into a fake login page. In this case the bait was the kind of message a newsroom sends every day: a colleague sharing a story.[3]

Once attackers hold a working password for a social media account, the only thing that normally stands in the way is a second login check, such as a one-time code sent to a trusted phone. In April 2013 Twitter did not offer one. The company introduced optional login verification by text message about a month later, after a string of takeovers of news organizations' accounts.[4] For AP, as for most companies then, a password was the whole lock.

The market side of the story made things worse. Many trades are made by computer programs that react to headlines faster than a person can read them. Traders blamed that automatic trading for the speed of both the drop and the rebound.[1] A trusted news account was, in effect, wired straight into the market.

How it was caught and what it cost

A pro-Syrian government hacking group calling itself the Syrian Electronic Army claimed responsibility the same day.[1] It had also taken over the accounts of other news outlets that year.[5]

On March 22, 2016, the Justice Department unsealed charges against 3 men it linked to the group. Prosecutors say 2 of them used spear-phishing, meaning phishing emails tailored to specific people, to break into accounts at government agencies, media groups and private companies, and they charged those 2 with a conspiracy that included a hoax about a terrorist attack, the fake AP report. The FBI added them to its cyber most wanted list and offered a $100,000 reward for information leading to their arrest. They were believed to be in Syria, and the charges remain allegations.[5]

The direct financial damage faded within minutes as prices recovered.[1] The lasting cost was trust: a single false line from a trusted source had shown how fragile an automated market can be.

The missing control

The missing control: two-factor login on the social media account.

With a second factor, a password captured on a fake login page is not enough on its own. The attacker also needs the code sent to a phone or app the organization controls. That would have turned a successful phishing email into a failed login attempt. In 2013 AP could not switch this on for Twitter because it did not yet exist there.[4] Today every major social platform offers it, and a brand account without it is relying on a password alone, which is where AP stood that afternoon.

What to do in your business

Watch the case
The fake tweet that wiped $136 billion in minutesDrops 2026-11-27
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Business Insurance (Reuters): Hackers seize AP Twitter feed, send market-moving bogus message
  2. Christian Science Monitor (AP): Hackers compromise Associated Press Twitter account, tweet false report of White House attack
  3. TechCrunch: AP Twitter hack preceded by a phishing attempt, news org says
  4. WeLiveSecurity (ESET): Twitter adds two-factor security after wave of attacks on media sites
  5. Nextgov: DOJ charges three Syrian Electronic Army hackers