Twitter attempts to overhaul its security policies after Bitcoin hack

Hackers targeted 130 accounts but ultimately tweeted from 45

Twitter has announced improvements to its security policies as a result of the spear-phishing attack on its platform earlier this month, which enabled hackers to tweet from 45 accounts belonging to prominent personalities, from Jeff Bezos and Bill Gates to US presidential candidate Joe Biden.

In an update to Twitter’s blog post, the social media platform vowed to improve its security measures in order to prevent similar incidents from happening in the future.

The company said that, starting immediately, it will work on improving its existing security tools, as well as expand existing workstreams across the entirety of the business.

It also said that it is working on improving methods used to detect "inappropriate access" to internal systems, and will prioritise security development across a number of teams. The social media platform also vowed to continue to organise ongoing company-wide phishing exercises throughout the year.

In the update, Twitter also confirmed that, although the attackers ultimately tweeted from 45 accounts, they had targeted 130, accessed the inboxes of 36, and managed to download the Twitter Data of 7.

Carl Wearn, head of e-crime at cyber security company Mimecast, said that spear-phishing “is becoming increasingly popular with cyber-criminals”.

“These kind of attacks prey on poor cyber-hygiene and attempt to mislead key employees, such as those in finance, HR or IT, and exploit human or process related vulnerabilities,” he said, adding that Mimecast’s recent State of Email Security report “found that 44% of UK respondents said that targeted spear-phishing attacks have increased in their organisation over the past 12 months”.

“Shockingly, our research found 56% of organisations do not provide awareness training on a frequent basis, which is leaving organisations incredibly vulnerable. The potential reputational damage organisations can suffer as a result of attacks such as this one, far outweigh the financial cost of proper training.”

Related Resource

Introducing VMDR: Vulnerability Management, Detection and Response

The all-in-one vulnerability management service

Download now

Wearn advised businesses to use strong passwords, multi-factor authentication, as well as “clear processes of chains of authorisation”.

Last week, two former Twitter staff members revealed that more than 1,000 Twitter employees and contractors could have had access to the same internal tools that are believed to have allowed cyber criminals to obtain control over the accounts.

Featured Resources

Edge-enabled mobility of the future

Turning vehicle data into value

Download now

Modern networking for the borderless enterprise

Five ways top organisations are optimising networking at the edge

Download now

Address multi-cloud configuration risks

Cloud security challenges and how to overcome them

Watch now

The total economic impact of IBM Security Verify

Cost savings and business benefits enabled by IBM Security Verify

Download now

Recommended

Monero miners target cloud-native development environments
cryptocurrencies

Monero miners target cloud-native development environments

5 Mar 2021
High-risk email security threats increased by 32% last year
phishing

High-risk email security threats increased by 32% last year

3 Mar 2021
Malicious ‘dependency confusion’ packages are stealing password files
hacking

Malicious ‘dependency confusion’ packages are stealing password files

2 Mar 2021
Hackers steal 70GB of data from far-right social network Gab
social media

Hackers steal 70GB of data from far-right social network Gab

1 Mar 2021

Most Popular

UK gov flip-flops on remote work, wants it a standard for all jobs
flexible working

UK gov flip-flops on remote work, wants it a standard for all jobs

5 Mar 2021
Star Alliance passenger data stolen in SITA data breach
data breaches

Star Alliance passenger data stolen in SITA data breach

5 Mar 2021
How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

26 Feb 2021