How the 2020 Twitter hack happened: a fake help desk call and an admin tool
The biggest hack in Twitter's history did not start with malware. It started with phone calls to employees working from home, from people claiming to be the company's own IT help desk.[1] This case file covers how those calls led to an internal admin tool, how the bitcoin scam that followed was traced, and the one control that would have contained it.
What happened
On the afternoon of July 14, 2020, callers began phoning Twitter employees and saying they were from the IT help desk, following up on problems with the company's VPN, the secure connection staff used to reach internal systems from home. Several employees reported the calls as suspicious. At least one believed them.[1]
The next day the intruders moved in stages. By 3:18 p.m. they were taking over accounts belonging to cryptocurrency companies. Between 4:17 p.m. and 6:05 p.m. they seized a long list of verified accounts, including those of Joe Biden, Barack Obama and Jeff Bezos, and posted messages promising to send back double any bitcoin sent to a given address.[1][5]
In all, 130 accounts were targeted. Tweets went out from 45 of them, private message inboxes were opened on up to 36, and account data was downloaded for 7.[1][3] The scam collected about $118,000 in bitcoin.[1] Alongside the celebrity posts, the group also grabbed rare short usernames, the kind that resell for thousands of dollars.[5]
How they got in
The calls pointed employees to a website built to look like Twitter's real VPN login page. As a worker typed in a username and password, the intruders used the same details on the real system at the same moment, which let them get past the extra login check as well.[1] New York regulators noted that the app-based second factor Twitter used could be defeated this way and recommended hardware security keys, which do not work on a look-alike site.[1]
The first employees fooled did not have the access the intruders wanted. So they used that first foothold to learn how Twitter's internal systems worked and which staff could use the account support tools, then went after those people next.[3] Those tools existed for ordinary jobs such as fixing accounts and enforcing rules, and they could change the email address and security settings on almost any account. More than 1,000 Twitter employees had access to them.[1]
The regulators also found that Twitter had gone without a chief information security officer since December 2019, 7 months before the attack.[1]
How it was caught
The scam was public from the first tweet, so the question was who was behind it. Bitcoin moves on a public ledger, which gave investigators a trail to follow. Three people were later charged.[4]
The central figure was a 17-year-old in Florida.[1][4] On March 16, 2021, he pleaded guilty to fraud charges in state court and was sentenced to 3 years in juvenile prison followed by 3 years of probation, the maximum under Florida's youthful offender law.[4]
What it cost
A British man, Joseph James O'Connor, was extradited from Spain in April 2023 and pleaded guilty on May 9, 2023, to charges covering his part in the Twitter hack along with a string of other crimes, including stolen cryptocurrency and stalking. On June 23, 2023, he was sentenced to 5 years in federal prison and ordered to forfeit about $794,000.[2]
For Twitter the cost was mainly trust. After the attack it significantly cut back who could use its account management tools.[3] New York's financial regulator went further, publishing a report in October 2020 that called for large social media companies to face cybersecurity rules and oversight like banks do.[1]
The missing control
The missing control: strict limits on who can use internal admin tools. A tool that can take over any account should be in very few hands, need a second person's approval for sensitive changes, and be watched for unusual use.
Every one of those would have narrowed this attack. With a small group of users, the callers would have had far fewer targets to trick. With a second approval step on email and password changes to high-profile accounts, one fooled employee would not have been enough. The regulators recommended exactly this: access only as far as each job needs, regular review of who still has it, a second employee's sign-off for critical actions, and monitoring for odd activity.[1] Phishing-resistant login keys would have closed the door the calls opened.
What to do in your business
- List who has admin rights. Write down every person who can reset passwords, change bank details or manage accounts in your email, payroll and banking systems. Remove anyone who does not need it this month.
- Add a second sign-off. For changes to payment details or to the accounts of owners and managers, require approval from someone other than the person making the change.
- Tell staff how IT will contact them. Agree that no one will ever be asked to log in through a link given on a phone call, and that anyone who gets such a call hangs up and calls IT back on a known number.
- Use security keys for admin accounts. Physical keys or passkeys for your most powerful logins stop a fake login page from working.
- Review access every quarter. Check who still has admin rights and turn on alerts for unusual admin activity where your systems allow it.
Twitter 2020: the phone calls that hijacked Obama, Musk and Gates: the long read behind the CL06 episode, chapter by chapter.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- How the MGM Resorts cyberattack happened: the help desk call that cost $100 million
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- New York State Department of Financial Services: Twitter Investigation Report (October 2020)
- U.S. Department of Justice: U.K. citizen sentenced to five years in prison for cybercrime offenses
- TechCrunch: Twitter says phone spear phishing attack used to gain network access in crypto scam breach
- The Record: Teenage Twitter hacker pleads guilty, will serve 3 years in prison
- Denver7 (Scripps): Twitter hackers got access to accounts by posing as IT desk employees, report says