Twitter Bitcoin Scam Fueled by Internal Tool Access and SIM Swappers

A massive Twitter breach compromises high-profile accounts to promote a bitcoin scam, netting attackers over $100,000. Evidence suggests the perpetrators are experienced SIM swappers who social-engineered a Twitter employee.

Twitter faces unprecedented chaos as a massive cyberattack hijacks the accounts of prominent politicians, tech executives, and celebrities to promote a bitcoin scam. The attackers trick or coerce a Twitter employee into handing over access to internal administrative tools, allowing them to seize control of highly-visible verified profiles like those of Joe Biden, Elon Musk, and Barack Obama. By directing followers to a fraudulent cryptocurrency wallet, the perpetrators successfully collect approximately $117,000 in bitcoin from unsuspecting users.

Security researchers point to strong evidence linking this breach to the underground community of SIM swappers. These criminals specialize in bribing, hacking, or coercing mobile phone company employees to hijack phone numbers and take over social media accounts. This specific group maintains a deep obsession with acquiring "OG" accounts, which are highly coveted profiles featuring short or unique usernames that confer elite status within their hacking circles.

Twitter publicly confirms that a coordinated social engineering attack targets employees with access to internal systems. The company actively investigates the full scope of the intrusion to determine exactly what other malicious activities the attackers conduct or what sensitive internal information they access while inside the network. This devastating event highlights the severe risks of insider threats and the extreme vulnerability of social media platforms when administrative tools fall into the wrong hands.

Read More at the original source →