SIM Swap Attack Compromises Twitter CEO Jack Dorsey's Account

A hacker takes over Jack Dorsey's Twitter account using a SIM swap attack, posting rogue tweets through the platform's SMS service. Twitter secures the account and blames the security breach on a mobile provider oversight.

A hacker compromises Twitter CEO Jack Dorsey's account and posts a stream of rogue tweets, including racial slurs, to his 4.21 million followers. The unauthorized tweets appear to come from Cloudhopper, a service Twitter acquired in 2010 to handle SMS functionality. The account responsible for claiming credit for the takeover faces immediate suspension from the platform.

Twitter investigates the incident and attributes the breach to a security oversight by Dorsey's mobile provider. This oversight allows an unauthorized person to compose and send tweets via text message by compromising the phone number associated with the account. The method strongly suggests that Dorsey falls victim to a SIM swapping attack, which bypasses the need for his actual account password.

This high-profile breach is not the first time a major tech executive faces a Twitter hack, as Facebook CEO Mark Zuckerberg previously lost control of his account due to weak security practices. Twitter quickly resolves the situation by securing Dorsey's account and issuing an official statement about the SIM swap vulnerability. The company chooses not to publicly name the mobile provider involved in the security lapse.

Read More at the original source →