How a hacked AP Twitter account wiped $136 billion off stocks in 3 minutes
A single false sentence posted from a news agency's Twitter account briefly erased about $136 billion from the value of the S&P 500 on April 23, 2013.[1] This case file covers how the Associated Press lost control of its account, why the market reacted so fast, who was charged, and the one control that would have made a stolen password useless.
What happened
At 12:12 p.m. Eastern on Tuesday, April 23, 2013, AP staff received an email that looked like it came from a colleague. It had the subject line "News" and urged them to read an important article through a link dressed up as a story on a major newspaper's website. The link actually led to a fake page asking them to log in. At 12:29 p.m., AP's information security team warned all staff about it.[3]
A little after 1 p.m., the main @AP Twitter account, followed by millions of people, posted a short report of 2 explosions at the White House and said President Barack Obama had been injured. None of it was true.[1][2]
Markets reacted within seconds. The Dow Jones Industrial Average fell 143.5 points, just under 1%, and the S&P 500 lost about $136.5 billion in value. AP staff quickly said on other channels that the account had been hacked, the White House press secretary told reporters the president was fine, and within about 3 minutes prices began to climb back. Twitter suspended both @AP and a second AP account, @AP_Mobile.[1][2]
How they got in
AP said the hijacking was preceded by phishing attempts against its corporate network.[2] Phishing is an email designed to trick someone into typing a password into a fake login page. In this case the bait was the kind of message a newsroom sends every day: a colleague sharing a story.[3]
Once attackers hold a working password for a social media account, the only thing that normally stands in the way is a second login check, such as a one-time code sent to a trusted phone. In April 2013 Twitter did not offer one. The company introduced optional login verification by text message about a month later, after a string of takeovers of news organizations' accounts.[4] For AP, as for most companies then, a password was the whole lock.
The market side of the story made things worse. Many trades are made by computer programs that react to headlines faster than a person can read them. Traders blamed that automatic trading for the speed of both the drop and the rebound.[1] A trusted news account was, in effect, wired straight into the market.
How it was caught and what it cost
A pro-Syrian government hacking group calling itself the Syrian Electronic Army claimed responsibility the same day.[1] It had also taken over the accounts of other news outlets that year.[5]
On March 22, 2016, the Justice Department unsealed charges against 3 men it linked to the group. Prosecutors say 2 of them used spear-phishing, meaning phishing emails tailored to specific people, to break into accounts at government agencies, media groups and private companies, and they charged those 2 with a conspiracy that included a hoax about a terrorist attack, the fake AP report. The FBI added them to its cyber most wanted list and offered a $100,000 reward for information leading to their arrest. They were believed to be in Syria, and the charges remain allegations.[5]
The direct financial damage faded within minutes as prices recovered.[1] The lasting cost was trust: a single false line from a trusted source had shown how fragile an automated market can be.
The missing control
The missing control: two-factor login on the social media account.
With a second factor, a password captured on a fake login page is not enough on its own. The attacker also needs the code sent to a phone or app the organization controls. That would have turned a successful phishing email into a failed login attempt. In 2013 AP could not switch this on for Twitter because it did not yet exist there.[4] Today every major social platform offers it, and a brand account without it is relying on a password alone, which is where AP stood that afternoon.
What to do in your business
- Turn on two-factor login for every social account. Facebook, Instagram, X, LinkedIn, TikTok and YouTube all support it. Use an authenticator app or security key where possible rather than text messages.
- Protect the email behind them. Whoever controls the email address on a social account can reset its password, so that inbox needs two-factor login too.
- Stop sharing one password. Use each platform's business or team tools so every person logs in as themselves, and remove people when they leave.
- Warn staff fast. When someone reports a suspicious email, send a short alert to everyone, as AP's security team did within 17 minutes.
- Have a hijack plan. Write down who contacts the platform, who posts a correction on your other channels, and how customers can check what is real.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Business Insurance (Reuters): Hackers seize AP Twitter feed, send market-moving bogus message
- Christian Science Monitor (AP): Hackers compromise Associated Press Twitter account, tweet false report of White House attack
- TechCrunch: AP Twitter hack preceded by a phishing attempt, news org says
- WeLiveSecurity (ESET): Twitter adds two-factor security after wave of attacks on media sites
- Nextgov: DOJ charges three Syrian Electronic Army hackers