Back to the archive

The encyclopedia · Software & IT · Operational decision · 2020

A 17-year-old phoned Twitter's help desk — and took over Obama, Musk and Biden's accounts

Hackers phoned Twitter's help desk and tricked employees into giving admin access. They hijacked Obama, Musk and Biden's accounts for a Bitcoin scam.

Twitter · 2020-07

What happened

On July 15, 2020, a group of hackers — led by 17-year-old Graham Ivan Clark — used a phone-based social engineering attack ('vishing') to trick Twitter employees into providing access to internal administrative tools. With these tools, the hackers took control of 130 high-profile accounts, including Barack Obama, Elon Musk, Joe Biden, Bill Gates and Apple.

The compromised accounts posted a Bitcoin scam promising to double any cryptocurrency sent to a specific address. The scam collected approximately $117,000 in Bitcoin before Twitter regained control. The attack was not a technical exploit — it was a human one: the hackers talked their way into the admin panel.

The case exposed the vulnerability of even the most prominent technology platforms to social engineering. Twitter's internal tools gave employees broad access to user accounts, and the authentication for those tools was insufficient to resist a phone call from a convincing teenager. The incident prompted Twitter (and the broader industry) to strengthen internal access controls and implement hardware security keys for administrative functions.

Why it happened

  • Hackers used phone-based social engineering to trick Twitter employees into providing admin access.
  • Twitter's internal tools gave broad access to user accounts with insufficient authentication.
  • 130 high-profile accounts were hijacked, including Obama, Musk, Biden and Gates.
  • The attack was not a technical exploit — it was a human one.
What it cost130 accounts hijacked; $117K Bitcoin scam; brand damagecostly

The lesson

The strongest encryption is useless when an employee hands over the keys. Twitter's hack was a phone call, not a code exploit. Admin access must require more than a convincing voice.

Aftermath

Graham Ivan Clark was sentenced to three years in prison. Twitter implemented hardware security keys for admin access and overhauled its internal tools. The case is cited as the definitive example of social engineering risk in platform security.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →