Skip to content

2020-07-15 (incident) · US · Twitter

Twitter account takeover via fake IT help desk calls, 2020

Sentence handed down.

On 14 and 15 July 2020, callers claiming to be from Twitter's IT help desk phoned employees about VPN problems and steered them to a phishing site that copied the real VPN login. With the captured credentials the hackers reached internal account tools, compromised 130 accounts and posted a bitcoin scam from high-profile ones. The New York Department of Financial Services found they took over $118,000 in bitcoin. Joseph James O'Connor was sentenced in 2023 for his role in the conspiracy.

$118,000 (stolen; The New York DFS report says the hackers took over $118,000 worth of bitcoin through the scam posts.)

Timeline

  1. 2020-07-14 Callers posing as Twitter's IT help desk start phoning employees about VPN problems and direct them to a look-alike VPN login site.
  2. 2020-07-15 Using internal tools, the hackers hijack high-profile accounts and post a bitcoin scam; 130 accounts are compromised in total.
  3. 2020-10-01 In October 2020 the New York Department of Financial Services issues its investigation report on the incident.
  4. 2023-05-09 Joseph James O'Connor pleads guilty in the Southern District of New York to charges that include his role in the July 2020 Twitter hack.
  5. 2023-06-23 O'Connor is sentenced to five years in prison.

Lessons

Scam types: Help desk password and MFA reset impersonation, Fake airdrop or giveaway · Techniques: Voice phishing (vishing)

Sources

  1. NY DFS: Twitter Investigation Report (October 2020) (Regulator, primary, accessed 2026-09-24)
  2. DOJ SDNY: U.K. citizen sentenced to five years in prison for cybercrime offenses (Law enforcement, primary, accessed 2026-09-24)