how a social engineering attack DESTROYED Twitter (feat. Marcus Hutchins) // Twitter Hack 2020

how a social engineering attack DESTROYED Twitter (feat. Marcus Hutchins) // Twitter Hack 2020

Source: YouTube · NetworkChuck · published Jul 22, 2020 · 21:09

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The high-profile Twitter hack was executed not through technical exploits, but by manipulating employees via social engineering and bribery to gain internal admin access 4:42-5:05.

Key Takeaways:
• The attackers bypassed security controls like two-factor authentication by exploiting human vulnerabilities rather than technical network weaknesses 1:38-1:53.
• Sources indicate the hackers bribed a Twitter employee named "Kirk" to gain access to an internal admin panel, allowing them to control high-profile accounts 5:20-8:01.
• Social engineering tactics range from physical methods like tailgating into offices to digital schemes like sim-hijacking or fake login portals to steal credentials 2:30-3:52.
• The incident highlights that employee training is the most critical defense against social engineering, as even the most sophisticated security infrastructure can be compromised by manipulated humans 18:48-19:06.

The vulnerability exposed by this attack suggests that social media accounts should be viewed with less privacy assumption due to the potential for state actors or criminals to exploit insider access.

Sources:

  • 4:42-5:05 Twitter's official statement on the manipulation of employees.
  • 1:38-1:53 Explanation that hackers targeted people rather than systems.
  • 5:20-8:01 Details on the bribe payment to the insider.
  • 2:30-3:52 Examples of human and computer-based social engineering attacks.
  • 18:48-19:06 Conclusion on the importance of employee training over just "magic boxes."

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

last week twitter was hacked and it was a pretty big one high-profile twitter accounts like bill gates elon musk president obama joe biden kanye west all taken over tweeting out a cryptocurrency scam how did this happen in this video we're gonna break that down i also brought in marcus hutchins a famous hacker known for stopping the wannacry ransomware and i got his take on this twitter hack you can tweet from any account on the entire platform you could do anything you could crash the stock market you could start a war you could swing the election you could really do anything and that's what scares me you need to learn learn learn hacking [Music] [Music] in this twitter hack hackers somehow gain access to internal twitter admin tools tools that gave them complete access to high-profile tw…