US officials demand answers to Twitter hacking; company has no security chief
Twitter had stepped up its search for a chief information security officer in recent weeks, two people familiar with the effort told Reuters, before the breach of high-profile accounts on Wednesday raised alarms about the platform’s security.
The FBI’s San Francisco division is leading an inquiry into the Twitter hacking, it said in a statement, as more Washington lawmakers called for an accounting of how it happened.
For all the latest headlines follow our Google News channel online or via the app.
The law enforcement agency said hackers committed cryptocurrency fraud after seizing control of the Twitter accounts of celebrities and political figures, including Joe Biden, Kim Kardashian, Barack Obama and Elon Musk.
A day after the breach, it was not clear if the hackers could see private messages sent by account holders, although Twitter said it had no evidence that attackers had been able to access passwords.
The company said that it was continuing to lock accounts that had changed passwords in the past month, but said “we believe only a small subset of these locked accounts were compromised.” Twitter declined to comment on the job search.
In a sign of how much the attacked unnerved US lawmakers, both Democrats and Republicans showed rare bipartisan agreement that Twitter must better explain how the security lapse happened and what it was doing to prevent future attacks.
Read more:
Anonymous hackers release 269 GB database of data from 200 US police departments
Twitter bans Wikileaks-style DDoSecrets for leaking hacked US police documents
“This hack bodes ill for November balloting,” US Senator Richard Blumenthal, a Democrat, said in a statement scolding Twitter for “its repeated security lapses and failure to safeguard accounts.”
Echoing a similar sentiment, Representative Jim Jordan, the top Republican on the House Judiciary Committee, asked what would happen if Twitter allowed a similar incident to occur on Nov. 2, a day before the US presidential election.
Jordan said he remained locked out of his Twitter account as of Thursday afternoon.
President Donald Trump, a prolific Twitter user, was planning to continue tweeting and his account was not jeopardized during the attack, spokeswoman Kayleigh McEnany said.
The White House had been in “constant contact with Twitter over the last 18 hours” to keep Trump’s Twitter feed secure, she said.
Twitter said hackers had targeted employees with access to its internal systems and “used this access to take control of many highly-visible (including verified) accounts.”
Other high-profile accounts that were hacked included rapper Kanye West, Amazon founder Jeff Bezos, investor Warren Buffett, Microsoft co-founder Bill Gates, and the corporate accounts for Uber and Apple.
The company, which has been without a security chief since December, said the hackers conducted a “coordinated social engineering attack” against its employees.
Some security experts who have been studying the hack from outside believe there could be multiple actors involved.
Their theory is that access to the employee tool, which should have been more closely monitored, spread among people interested in prestige accounts for bragging rights or money. It could have spread further, to spies or pranksters.
In an extraordinary step, Twitter temporarily prevented many verified accounts from publishing messages as it investigated the breach.
The hijacked accounts tweeted out messages telling users to send bitcoin. Publicly available blockchain records show the apparent scammers received more than $100,000 worth of cryptocurrency.
As of Thursday, Twitter was continuing to block tweets containing the bitcoin addresses the scammers had used. Facebook appeared to have enabled a similar security feature on its Messenger service temporarily on Wednesday, but did not respond to queries on whether it had also been targeted in the attack.
Frank Pallone, a Democrat who chairs the House Energy and Commerce Committee that oversees a sizeable portion of US tech policy, said the company needed to explain how the hack took place.
The US House Intelligence Committee was in touch with Twitter regarding the hack, according to a committee official who did not wish to be named.
-
Hackers convinced, paid Twitter employee to help them hijack accounts: Motherboard
A Twitter employee assisted hackers who took over several high-profile accounts on the social media platform on Wednesday, according to two hackers ... World News -
Campaign for Twitter to move office out of Dubai under scrutiny for Qatar links
A campaign for Twitter to move its regional headquarters from Dubai to another country in the region was dismissed by media experts on Sunday, who ... Gulf -
Twitter removes accounts associated with China, Russia, Turkey
Twitter on Thursday said it removed more than 170,000 accounts tied to a Beijing-backed influence operation that deceptively spread messages favorable ... Digital