Security News > 2020 > July > Breach of high-profile Twitter accounts caused by phone spear phishing attack
Twitter has confirmed that the breach of several high-profile accounts that occurred on July 15 was caused by a phone spear phishing attack that targeted a small number of employees.
Using the credentials of the affected employees, the attackers managed to compromise 130 different Twitter accounts, including those of Bill Gates, Jeff Bezos, Elon Musk, Joe Biden, and Barack Obama, according to Twitter.
Spear phishing refers to a type of phishing attack in which criminals email specific individuals with the goal of gaining their account credentials or other sensitive information.
Twitter didn't explain what it meant by a "Phone spear phishing attack." This could mean that the attackers actually called certain employees by phone rather than using email to find out their credentials, or it could mean targeted employees received a message by phone or email convincing them to call a certain person masquerading as a legitimate Twitter administrator.
"A phone phishing attack would be similar , but instead the targets are telephoned and the criminal would attempt to elicit information, in this case, probably their account credentials," Mike McLellan, senior security researcher for Secureworks, told TechRepublic.
News URL
Related news
- Astaroth Banking Malware Resurfaces in Brazil via Spear-Phishing Attack (source)
- Midnight Blizzard Escalates Spear-Phishing Attacks On Over 100 Organizations (source)
- Australian Organisations Targeted by Phishing Attacks Disguised as Atlassian (source)
- Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- GitHub, Telegram Bots, and ASCII QR Codes Abused in New Wave of Phishing Attacks (source)
- Tech giant Nidec confirms data breach following ransomware attack (source)
- Samsung phone users under attack, Google warns (source)
- Henry Schein discloses data breach a year after ransomware attack (source)
- Windows infected with backdoored Linux VMs in new phishing attacks (source)