Reply to post: Re: Your passwords are safe - phew!

Twitter admits 130 A-lister accounts compromised to promote Bitcoin scam after 'social engineering' attack

Phil Koenig

Re: Your passwords are safe - phew!

The attackers apparently did 2 things on the targeted accounts with the admin creds they gained access to (apparently via social engineering), which are standard admin tasks:

1) Disabled 2FA if enabled

2) Reset the associated email account to an account under their control

Once they had control of the linked email accounts (and with 2FA disabled) they could send password reset requests and at that point they effectively owned the accounts.

None of that discounts the fact that Twitter is incompetent here - in fact I think they are grossly incompetent.

And this also highlights the folly of making access to a particular email address a critical part of any account's so-called "security".

It's not much better than your bank giving someone else access to your account if they are wearing the same brand of shoes you wear.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon