Security News > 2020 > October > Security much? Twitter should have had a CISO to prevent Bitcoin hack, says US state financial body

American financial regulators in New York have demanded Twitter be subject to harsher rules following the July hacks of prominent users' accounts - as CEO Jack Dorsey furiously backpedals after his website censored a news article from a US newspaper.
The New York State Department of Financial Services demanded that Twitter be subject to more "Cybersecurity protections", controlled and overseen, naturally, by itself.
DFS blamed Twitter's lack of a chief information security officer for the hack as well as the platform's shift to homeworking.
It identified the attack vector as "Vishing" - voice-enabled phishing - where the hackers made phonecalls to Twitter posing as legitimate staffers and claiming to be struggling with corporate VPN access: "Armed with these personal details, the Hackers successfully convinced several Twitter employees that they were from Twitter's IT department and stole their credentials," said DFS. Twitter censorship kerfuffle.
Separately, Twitter CEO Jack Dorsey was forced into a very public reverse ferret after Twitter staffers blocked a problematic New York Post article from being shared on the platform because it had been labelled as "Potentially harmful."
News URL
Related news
- CISOs don’t invest enough in code security (source)
- China-Linked Cyber Threat Group Hacks US Treasury Department (source)
- CISA says recent government hack limited to US Treasury (source)
- US Treasury hack linked to Silk Typhoon Chinese state hackers (source)
- GitHub CISO on security strategy and collaborating with the open-source community (source)
- What 2024 taught us about security vulnerabilties (source)
- US sanctions Chinese firm, hacker behind telecom and Treasury hacks (source)
- CISOs are juggling security, responsibility, and burnout (source)
- Zscaler CISO on balancing security and user convenience in hybrid work environments (source)
- How CISOs can balance security and business agility in the cloud (source)