Twitter has suffered a massive security breach after dozens of prominent accounts were hijacked and displayed scam messages requesting transfers of bitcoin to an anonymous account controlled by the hackers.
The attack unfolded on Wednesday evening, with the affected accounts including presidential candidate Joe Biden, Elon Musk, Jeff Bezos, Bill Gates, Kanye West and Kim Kardashian West.
Former President Barack Obama, the most popular account on Twitter with more than 120 million followers, was also targeted, as were the corporate accounts of Apple and Uber.
In an urgent response to the breach, Twitter took the extraordinary step of temporarily blocking all verified accounts from tweeting, according to UN chief of the cybercrime Neil Walsh. Shares in the company fell nearly 4 percent in after-hours trading.
'While account take-overs are commonplace, this would be appear to be a compromise on an unprecedented scale,' Brett Callow, a threat analyst at cybersecurity firm Emsisoft, told DailyMail.com of the breach.
Former President Barack Obama, the most popular account on Twitter with more than 120 million followers, was targeted by hackers who posted a bitcoin scam to his account
'Whether it’s the result of a breach at a third-party, a weakness in Twitter’s own security or something else entirely is impossible to say,' he added.
The widespread and coordinated nature of the attack led some experts to speculate that a Twitter employee with administrative access had been hacked, or that a flaw in the login process was being exploited.
A Twitter spokesperson declined to immediately offer specifics on how the attack unfolded when reached by DailyMail.com.
'We are aware of a security incident impacting accounts on Twitter. We are investigating and taking steps to fix it. We will update everyone shortly,' the company said in a public statement. RELATED ARTICLES Previous 1 Next Elon Musk shares render of Tesla's 'Gigafactory' Berlin that... Google is experimenting with rub-on SMART TATTOOS that turn... Share this article Share
'You may be unable to Tweet or reset your password while we review and address this incident,' the company added in an update.
More than an hour after the first wave of hacks, Twitter prevented at least some verified accounts from publishing messages altogether.
It was not clear whether all verified users were affected but, if so, it would have a huge impact on the platform and its users. Verified users include celebrities and journalists, but also governments, politicians and heads of state.
Twitter shares fell nearly 4% in after-hours trading as the company froze verified accounts
Although individual Twitter accounts have been briefly breached in the past using stolen passwords, the scale of Wednesday's attack was unprecedented.
'This appears to be the worst hack of a major social media platform yet,' said Dmitri Alperovitch, who co-founded cybersecurity company CrowdStrike.
Other political figures impacted by the attack included Rep. Alexandria Ocasio-Cortez and former Democratic presidential candidate Mike Bloomberg.
Of the politicians affected by the breach, all appeared to be Democrats.
Biden's campaign was 'in touch' with Twitter, according to a person familiar with the matter. The person said the company had locked down the Democrat's account 'immediately following the breach and removed the related tweet.'
President Donald Trump's re-election campaign seized on the breach, with campaign spokesman Tim Murtaugh mocking the scam message as similar to Biden's policy proposals.
'I've seen creative ways to disguise a tax increase, but this takes the cake,' Murtaugh tweeted. 'Hacked account or not, this is a perfect metaphor for Biden's pitch to taxpayers: "Give me your money!"'
The fraudulent tweets all followed a similar formula, and directed potential victims to send bitcoin to the same anonymous wallet.
'I am giving back to my community due to COVID-19!' read the scam tweet posted to Obama's account.
'All Bitcoin sent to my address below will be sent back doubled. If you send $1,000, I will send back $2,000!' the fake message continued.
The message shared on Bezos' account stated he is 'only doing a maximum of $50,000,000.'
One scam tweet surfaced on Elon Musk's Twitter account around 4:30pm ET Wednesday
Amazon CEO Jeff Bezos was also among the victims targeted in the bitcoin scam
Most of the fraudulent tweets disappeared within minutes of first being posted, suggesting that Twitter administrators were playing whack-a-mole with the attacker.
Although many users knew the gesture was the evil working of a cybercriminal, others replied they sent money to the listed account.
Many Twitter users posted screenshots of bitcoin transfer receipts to the wallet listed in the scam, claiming they had been duped before realizing the scam.
Publicly available blockchain records show that the apparent scammers have already received more than $100,000 worth of cryptocurrency, with the amount still growing.
Several Twitter users claimed that they had fallen for the scam and sent bitcoin
Some experts said the incident has raised questions about Twitter's cybersecurity.
'It's clear the company is not doing enough to protect itself,' said Oren Falkowitz, former CEO of Area 1 Security.
Alperovitch, who now chairs the Silverado Policy Accelerator, said that, in a way, the public had dodged a bullet so far.
'We are lucky that given the power of sending out tweets from the accounts of many famous people, the only thing that the hackers have done is scammed about $110,000 in bitcoins from about 300 people,' he said.