Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

drcre8tive

macrumors regular
Jul 28, 2014
136
234
New Orleans
You might think it would be obvious that this was a hack, but in total $100,000 in bitcoins were sent. That means there is an equal number of morons out there. I'm guessing they are the same people who think masks are a personal choice and that dinosaurs were on Noah's ark.
 

MacCheetah3

macrumors 68020
Nov 14, 2003
2,095
1,074
Central MN
Some heads should roll and new internal processes should be put in place to prevent this in the future. But "wow. Just plain wow" is absolutely correct.
That scenario does presumably reveal security, sensible permission oversight.

1. Only the account owner should be able to modify an email address as it is a key form of notification. There isn't a good reason for anyone else, including a Twitter employee, to change this or a phone number.
2. Any account allowed to modify other accounts should also have automated restrictions:
A. Unusual login locations/devices should be verified (perhaps by a senior admin)
B. Only one or two modifications within an hour or some other reasonable period (attempting more should, again, alert a senior admin)
 

C DM

macrumors Sandy Bridge
Oct 17, 2011
51,390
19,458
Did someone here actually fell in the trap?
There's just above $100k worth of BTC in that account so I'd say some people did. I wonder how much he paid to get access and if that was worth it... $100k doesn't seem like much considering the circumstances and someone losing his job because of it.
It's not a scam, it's an IQ test where the test taker sets their own fee.
You might think it would be obvious that this was a hack, but in total $100,000 in bitcoins were sent. That means there is an equal number of morons out there. I'm guessing they are the same people who think masks are a personal choice and that dinosaurs were on Noah's ark.
You have to wonder though how those who would potentially fall for something like this would actually also be those who even know what bitcoin is, let alone to use it and actually have access to some.
 
  • Like
Reactions: yellow8

farewelwilliams

Suspended
Jun 18, 2014
4,966
18,041
What I gathered from your original post was that you were suggesting that Twitter should implement an algorithm that detects tweets such as these, not the exact one in question perse. Yes they could simply delete any tweet containing this specific bitcoin address. I don't think it would make sense to delete all tweets which contain any bitcoin address though. There are legitimate causes that accept bitcoin.
actually, turns out they just implemented it
 

T-R-S

macrumors 6502
Sep 25, 2010
455
280
Silicon Valley
inside job rogue employees
I find it very Ironic that people think Covid 19 and masks are a hoax and this obvious scam is the real deal...
 

BenTrovato

macrumors 68040
Jun 29, 2012
3,035
2,198
Canada
You might think it would be obvious that this was a hack, but in total $100,000 in bitcoins were sent. That means there is an equal number of morons out there. I'm guessing they are the same people who think masks are a personal choice and that dinosaurs were on Noah's ark.

Seriously... the CDC said that 100% of the donations to the bitcoin address were from mask wearers. They then adjusted the values to 94%. Only 6% of non mask wearers made the donations. Crazy bunch!
 
  • Like
Reactions: Romanesq

Romanesq

macrumors 6502a
Jun 16, 2003
914
90
Hoboken
So after eight pages of people patting themselves on the back talking about hackers, hack this way, hack that way, the entire scam was an inside job by a ****ter employee who did it for $2,000. I called it an inside job yesterday and a day later it turns out true.

All they found of him was a mask he left.

 

Apple_Robert

Contributor
Sep 21, 2012
34,329
49,658
In the middle of several books.
So after eight pages of people patting themselves on the back talking about hackers, hack this way, hack that way, the entire scam was an inside job by a ****ter employee who did it for $2,000. I called it an inside job yesterday and a day later it turns out true.

All they found of him was a mask he left.

You didn’t call it an inside job on here that i can see. Are you wanting a gold star or something for guessing correctly?
 

Romanesq

macrumors 6502a
Jun 16, 2003
914
90
Hoboken
You didn’t call it an inside job on here that i can see. Are you wanting a gold star or something for guessing correctly?

No, I was not here yesterday. I called it yesterday on another website. Entertaining how people here didn't have much of an idea on how so many accounts were being compromised not hacked by an inside job.

The ****ter employee gave it up and also revealed in their tool panel how ****ter has created blacklist censorship tools. They won't comment about them even as they publicly claimed they don't censor people.

This is getting better and better.
 

guerro

macrumors 6502
Jul 18, 2002
268
494
Parts Unknown


Apple's Twitter account has been breached by bitcoin scammers who have also hacked the Twitter accounts of Tesla CEO Elon Musk, Amazon CEO Jeff Bezos, Microsoft CEO Bill Gates, and more.

apple_bitcoin_hack.jpg

Apple users should be careful not to believe the fake tweet, which is a scam to collect bitcoin. Twitter has been deleting the fake tweets, but the scammers who have breached the accounts have been repeatedly posting them.

The tweet that was posted on the Apple Twitter account has since been deleted. Given the number of high profile accounts that have been breached, the hack may have originated from a Twitter security vulnerability.

Apple does not actually use its official Apple Twitter account on the platform, reserving it for sending out reminders ahead of events and advertisements.

Update: Twitter says that it's looking into the security breach and will provide an update after implementing a fix.



Update 2: Twitter appears to have disabled all tweets from verified accounts, so no one with a verified account is able to tweet at this time.



Update 3: Most verified Twitter accounts are now once again able to tweet. Twitter is still working on fully fixing the issue.



Article Link: Apple's Twitter Account Hacked by Bitcoin Scammers

Sounds more like social engineering than actual hacking.
 

7493920

Cancelled
Mar 11, 2020
50
49
Scams by their very nature target the gullible, ill-informed or desperate. They don’t expect or need the majority of people to fall for it. It’s only ever a small minority that do.
Someone hasn’t seen The Music Man.
 

PinkyMacGodess

Suspended
Mar 7, 2007
10,271
6,226
Midwest America.
Well deserved, these social sites only contribute trash to mankind.

Someone said that 'Facebook is a cesspool'. I couldn't agree more. I finally got over the feeling that I would be missing something, and dropped FB. I sure am missing a lot. All the petty BS... Oh, and the stalking. (I actually found an old girlfriend on FB, totally by accident. I wished her well, and blocked her)
 

MacCheetah3

macrumors 68020
Nov 14, 2003
2,095
1,074
Central MN
Read Twitter’s update on the huge hack — 8 accounts may have had private messages stolen

Even if it was:
Twitter previously confirmed that its own internal employee tools were used to facilitate the account takeovers, and suspected that its employees had fallen for a social engineering scam — now, the company is going further to say definitively that the attackers “successfully manipulated a small number of employees and used their credentials to access Twitter’s internal systems, including getting through our two-factor protections.”
The employee account restrictions I mentioned earlier would have caught the activity sooner and at least slowed things down. Companies don’t seem to realize how dangerously unpredictable and destructive the human factor can be at any/every level.
 

icanhazmac

Contributor
Apr 11, 2018
2,520
9,450
IDK... this doesn't necessarily seem like anything harder than a script kiddie could figure out. Learn the login of somebody at Twitter, log into their account at AWS, then find the admin scripts. Use admin scripts to tweet as the 1000 accounts with the most followers.

To a kid who hasn't worked, this could certainly seem like a huge amount of money that they've brought in.

What better idea do you have for how to make money you've broken in?
A Florida teenager, who is accused of being the "mastermind" behind the July hacking of social media site Twitter, has been arrested

@ArtOfWarfare called it! Kiddies to blame! You win the internet today!
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.