Twitter Confirms Hackers Accessed Direct Messages of 36 Targeted Accounts

Twitter admits that last week's massive Bitcoin scam hack exposes the direct messages of 36 high-profile accounts, including a Dutch elected official. The company states there is no evidence that passwords or the DMs of other current or former politicians are compromised.

Twitter admits that hackers access the direct message inboxes of 36 high-profile accounts during last week's massive security breach. The attackers use a coordinated social engineering attack to gain entry to internal systems and tools, allowing them to take over 130 verified accounts to promote a lucrative Bitcoin scam.

The compromised direct messages include the inbox of a Dutch elected official, though Twitter claims it finds no indication that other current or former politicians experience DM breaches. The company also maintains that it has no evidence suggesting the attackers access any user passwords during the incident.

Twitter's messaging system is notoriously lacking in strong encryption, but it initially remains unclear exactly how much access the administrative tool provides to private inboxes. This disturbing security breach sparks serious concerns about internal access controls, and more updates are likely to follow as the investigation continues.

Read More at the original source →