Twitter 2020: the phone calls that hijacked Obama, Musk and Gates
On July 15, 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates and Apple all asked followers to send bitcoin, and nobody had broken Twitter's code to make it happen.[1] New York's financial regulator later found the attackers used no malware, no exploits and no backdoors, only phone calls and a fake login page.[1] This long read walks through the calls, the internal tool, the afternoon itself, the arrests, the regulator's findings, and the control that would have stopped it.
The phone calls to Twitter's remote workers
By July 2020, Twitter's staff had been working from home since March because of the pandemic. That meant heavy reliance on the company's VPN, the encrypted connection employees use to reach internal systems from outside the office, and frequent problems with it. A call from IT about the VPN was routine, not suspicious.[1]
On July 14 and 15, callers claiming to be from Twitter's IT help desk phoned employees about VPN trouble. They steered each employee to a website built to look like Twitter's real VPN login. As the employee typed a username and password into the fake page, the callers entered the same details into the genuine system in real time. That set off a real multi-factor prompt on the employee's phone, and some employees, believing they were helping IT fix the problem, approved it.[1] Twitter itself described the method as phone spear phishing, a targeted scam aimed at specific staff.[2]
The first people reached did not have access to anything powerful. But once inside, the callers could browse the company's intranet, learn how internal systems worked, and find out who did have access. Then they went back to the phones.[1]
The regulator's summary was pointed: the techniques were basic and closer to those of a traditional scam artist than a sophisticated hacking operation.[1] The weak point was a login process that a convincing caller could walk an employee through.
The internal admin tool with 1,000 users
Twitter ran internal account management tools so support staff could help users. Those tools could see account details, change the email address tied to an account and switch off its security settings. The regulator found that more than 1,000 Twitter employees had access to them.[1] With that many people holding the keys, the attackers only needed to fool one of the right ones.
They did. Between about 3 a.m. and 10 a.m. on July 15, the group was discussing and taking over so-called OG usernames: short, rare handles such as single letters or words that sell for real money in online trading circles.[1] Justice Department investigators later found one member advertising on a hacking forum that he could change the email on any Twitter account for $250, or sell direct access for $2,000 to $3,000.[5]
Around 2 p.m., the group posted screenshots of Twitter's internal tools from hijacked accounts. At 2:16 p.m., they took over a cryptocurrency trader's account. At 3:18 p.m., they seized the account of the exchange Binance, which triggered Twitter's incident response. Between 3:26 and 4:12 p.m., 10 more crypto-related accounts, including Coinbase, Gemini and Square, fell.[1]
The afternoon the world's biggest accounts posted a scam
At 4:17 p.m., the takeovers moved to the most followed people on the platform. Between then and 6:05 p.m., the attackers posted from the accounts of Elon Musk, Bill Gates, Barack Obama, Kim Kardashian West, Jeff Bezos, Warren Buffett, Kanye West, Joe Biden, Floyd Mayweather, Uber and Apple.[1] Each post carried the same basic promise: send bitcoin and get double back.
Twitter made its first public statement at 5:45 p.m. At 6:18 p.m., it took a step without precedent, locking many verified accounts so they could not tweet and restricting password changes.[1] For a few hours, heads of state, companies and news organizations were silenced on purpose. By 8:41 p.m., most accounts could tweet again, and Twitter said it restored access to most affected accounts by July 17.[1][2]
The final count from Twitter and the regulator was 130 accounts targeted, 45 used to send tweets, 36 with private message inboxes accessed, including a Dutch elected official, and 7 whose full account data was downloaded.[1][2] Passwords were not exposed, because Twitter did not store them in plain text.[2]
The scam collected about $118,000 in bitcoin. It would have been far more: cryptocurrency companies blocked more than 6,000 attempted transfers worth about $1.5 million, with Coinbase alone stopping about 5,670 of them, worth roughly $1.3 million.[1]
How investigators found a 17-year-old in Tampa
The same things that made the scam fast also made it traceable. Bitcoin moves on a public ledger, and IRS Criminal Investigation analysts worked to link the scam wallets to real people. The FBI's San Francisco division led the case with help from the Secret Service.[4] Forum posts advertising Twitter account access, and chat messages about buying usernames before the attack, gave investigators handles to follow.[5] A search warrant was served in Northern California on July 21.[5]
On July 31, 2020, just 16 days after the attack, federal prosecutors announced charges against a 19-year-old from the United Kingdom and a 22-year-old from Orlando, Florida.[4] A third person, a juvenile, was referred to state prosecutors in Tampa, Florida, and arrested the same day.[4][3] The regulator identified him as the primary attacker. He was 17, and this page does not name him.[1]
A fourth name came later. Joseph James O'Connor, a British man, took part in the conspiracy by discussing the purchase of access to high-profile accounts and agreeing to pay $10,000 for one, according to federal prosecutors.[6] His case also covered a SIM-swap scheme, in which criminals hijack a victim's phone number, that stole about $794,000 in cryptocurrency from a Manhattan company's executives in 2019.[6]
The pleas, the prison terms and the regulator's report
In March 2021, the Tampa teenager agreed to a plea deal on 30 felony counts, including organized fraud and unauthorized computer access. As a youthful offender he received 3 years in custody followed by 3 years of probation, with credit for about 7.5 months already served, and he surrendered the bitcoin from the scheme.[3]
O'Connor was extradited from Spain on April 26, 2023, pleaded guilty on May 9, 2023, and was sentenced on June 23, 2023, to 5 years in prison. He also had to forfeit $794,012.64.[6]
The New York Department of Financial Services, which examined the attack because several regulated crypto firms had their accounts hijacked, published its report in October 2020. It found that Twitter had been without a chief information security officer since December 2019, about 7 months before the attack. It found that over 1,000 employees could use the account tools. And it found that the company relied on app-based multi-factor prompts that an employee could be talked into approving.[1] The report went further, arguing that platforms this large should face regulation similar to systemically important banks.[1]
Twitter's own fix went to the heart of the problem. It moved its roughly 5,500 employees onto physical security keys, small USB or tap-to-connect devices, for internal system access, and reached full enrollment in 2021.[7] A security key checks that it is talking to the real website, so a fake login page gets nothing it can reuse, and a caller cannot talk anyone into approving one remotely.
Why a phone call beat Twitter
Trace the chain backward. The famous accounts fell because one internal tool could change their email and switch off their protections, and more than 1,000 people could use it.[1] The tool was reachable because an employee approved a login prompt for a caller who said he was IT. And the call worked because nothing in the process verified who was actually on the line, or whether the login page was real.[1]
Any one break in that chain would have limited the damage: fewer people with tool access, prompts that cannot be approved for someone else, or a rule that IT never asks for credentials by phone.
Timeline
| Date | What happened |
|---|---|
| Dec 2019 | Twitter's chief information security officer post falls vacant.[1] |
| Mar 2020 | Twitter staff shift to remote work and rely on the VPN.[1] |
| Jul 14–15, 2020 | Fake IT help desk calls lead employees to a phishing VPN page.[1] |
| Jul 15, 2020, 3:18 p.m. | Binance account seized; Twitter's incident response begins.[1] |
| Jul 15, 2020, 4:17–6:05 p.m. | Accounts of Obama, Biden, Musk, Gates, Apple and others post the bitcoin scam.[1] |
| Jul 15, 2020, 6:18 p.m. | Twitter locks many verified accounts.[1] |
| Jul 31, 2020 | Charges announced against 3 people, including a 17-year-old.[4] |
| Oct 2020 | New York DFS publishes its investigation report.[1] |
| Mar 2021 | The teenage ringleader takes a plea deal: 3 years plus 3 years of probation.[3] |
| 2021 | All Twitter employees move to physical security keys.[7] |
| Jun 23, 2023 | Joseph James O'Connor sentenced to 5 years.[6] |
The missing control
The missing control: phishing-resistant multi-factor login, such as hardware security keys, combined with admin tools limited to the few people who truly need them.
- Use security keys for admin accounts. Start with email, banking, domain, payroll and cloud admin logins. A key works only on the real site, so a fake page and a persuasive caller get nothing.
- Cut the list of admins. Write down everyone who can reset passwords, change account emails or turn off security settings. If the list is longer than the jobs that need it, shorten it.
- Set a rule: IT never asks for your password or a login approval by phone. Tell staff in writing, and repeat it. A call that asks for either is the attack.
- Verify support calls on a known number. If someone claims to be IT or a vendor, hang up and call back using a number you already have, not one the caller gives you.
- Alert on sensitive changes. Turn on notifications for email changes, security settings being switched off and new admin sign-ins, and make sure a real person reads them.
What it means now
The Twitter attack is now a standard teaching case because it shows how little technical skill a major breach can need. A few young people with phones beat a company with a large security budget by exploiting a remote workforce, a login prompt anyone could approve and an admin tool too many people could use.
The same approach has since been used against casinos, telecoms and tech firms. For a small business, the lesson is cheap to apply: logins that cannot be phished, a short admin list, and a habit of calling back before believing a voice on the phone.
How the 2020 Twitter hack happened: a fake help desk call and an admin tool: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- New York State Department of Financial Services: Twitter Investigation Report
- Twitter (X) Blog: An update on our security incident
- BleepingComputer: Teen hacker agrees to 3 years in prison for Twitter bitcoin scam
- US Department of Justice (N.D. Cal.): Three individuals charged for alleged roles in Twitter hack
- Krebs on Security: Three charged in July 15 Twitter compromise
- US Department of Justice (S.D.N.Y.): U.K. citizen sentenced to five years in prison for cybercrime offenses
- TechTarget: Twitter details internal Yubico security key rollout