  • he Twitter accounts of major public figures and corporations, including Joe Biden, Barack Obama, Elon Musk1, Bill Gates, Jeff Bezos and Apple were hijacked2 Wednesday, in a stunning4 show of force by hackers6.


    Twitter said it was aware of "a security incident" and "taking steps to fix it", but provided no further information hours after the hack5 began.


    The hack unfolded over the course of several hours, and it appeared that Twitter was only able to stop it by preventing verified accounts from tweeting at all – an unprecedented7 measure.


    The messages included the address of a bitcoin wallet whose balance grew rapidly to more than 11 BTC (more than $100,000) as the scam spread. Tweets with similar messages were repeatedly deleted and re-posted by some of the compromised accounts over the course of Wednesday afternoon.


    While the motives8 and source of the attack are not yet known, the coordinated9 hijacking10 of the verified communications streams of world leaders, celebrities11 and major corporate12 accounts was a frightening prospect13. Twitter has become a de facto wire service for the world and is used for official communications by governments during emergencies; a hack on the scale of Wednesday's attack could have been more disruptive or even dangerous.


    "The amount of damage this could cause is very high," said Douglas Schmidt, a computer science professor at Vanderbilt University. "These people could hold information gleaned14 from the hack for ransom15 in the future."范德比尔特大学计算机科学教授道格拉斯·施密特说:“这可能造成非常大的损害。这些人可以保存从此次入侵事件中收集到的信息,以便将来索取赎金。”

    Twitter issued a statement approximately 90 minutes after scam messages began being sent out by Musk's and Gates' accounts, as the attack was ongoing16.


    "We are aware of a security incident impacting accounts on Twitter," the company said on Twitter. "We are investigating and taking steps to fix it. We will update everyone shortly."推特公司发推文表示:“我们注意到一起安全事件影响了推特上的账户。我们正在调查并采取措施修复。我们很快就会向大家发布最新消息。”

    The company subsequently warned that some users would be unable to tweet or change their passwords as it worked to address the issue. The company appeared to be blocking verified users, whose accounts feature a blue checkmark to denote that Twitter has confirmed their identities, from tweeting.


    Twitter's stock price tumbled more than 3% in after hours trading.


    The hack probably targeted a vulnerability on Twitter's end rather than those of the individual account holders17, said John Ozbay, the chief executive of the privacy and security tool Cryptee. Most high-profile users probably engage two-factor authentication18, Ozbay said, and the hackers appeared to have enough control over the compromised accounts to "pin" a tweet. That would not have been possible if a hacked19 account were being controlled by SMS, as occurred when the Twitter CEO Jack3 Dorsey's own account was hijacked in 2019.


    Schmidt said that the attacks could be related to the fact that Twitter, like much of the rest of the tech industry, has transitioned to remote work during the coronavirus pandemic.


    "The likelihood of attacks like this increase when people are working remotely it is much easier for bad actors to impersonate someone through an email and gain access to their accounts," said Schmidt. "Assuming this wasn't someone inside Twitter trying to take revenge, it appears to be a spear phishing attack – someone who has access to admin privileges that can override20 two-factor authentication and strong passwords fell victim to a hack".


     12级    双语 


