Skip to main content

Hackers used scarily simple way to take over Twitter CEO Jack Dorsey’s account

Twitter CEO Jack Dorsey’s account fell victim to an old hacking method, bringing the technique back in the spotlight and raising fresh concerns about the social media platform’s security.

The hackers, who call themselves the Chuckling Squad, hijacked Dorsey’s account on Friday afternoon. They were able to tweet out offensive messages before Twitter took back control.

Twitter immediately launched an investigation into the security incident. There were a few theories on what exactly happened, though it appeared that the hackers posted the tweets from an app called Cloudhopper, which the social media platform bought in 2010.

https://twitter.com/TwitterComms/status/1167591003143847936

Cloudhopper allows users to post tweets by texting messages to a certain number. The service only requires a phone number to be linked to an account on the platform, and it looks like Dorsey had his linked.

The hackers were able to acquire Dorsey’s phone number through “a security oversight,” allowing them to send out tweets on his account through Cloudhopper. Regular users, meanwhile, should not worry that the security breach affected everyone on the service.

The method, called SIM swapping, convinces carriers to assign a phone number to a new phone that is in the hands of the attackers. Chuckling Squad has been using the technique for years, with prominent attacks against online influencers, according to The Verge. It also appeared that the group has something going on with AT&T, which is also Dorsey’s carrier. However, it remains unclear how exactly they acquired the Twitter CEO’s phone number.

This is not the first time that Dorsey’s account was compromised. Back in 2016, hackers associated with OurMine took over the account, claiming that they were testing the platform’s security, following takeovers on the Quora account of Google’s Sundar Pichai, and the Instagram, LinkedIn, Pinterest, and Twitter accounts of Facebook’s Mark Zuckerberg.

The new security incident involving Dorsey reveals that his Twitter account is set up like a regular user, with all the vulnerabilities that it entails. It is unclear why the company did not provide additional safeguards on Dorsey’s account to protect against attacks such as SIM swapping, even after their CEO was already targeted in the past.

Editors' Recommendations

Aaron Mamiit
Aaron received a NES and a copy of Super Mario Bros. for Christmas when he was 4 years old, and he has been fascinated with…
Facebook’s Twitter account taken over by hacker group OurMine
mark zuckerberg speaking in front of giant digital lock

Facebook's Twitter account was briefly hacked Friday afternoon by prominent group OurMine.

The tweet read, "Well, even Facebook is hackable but at least their security better than Twitter."

Read more
Police arrest suspect in hack of Twitter CEO Jack Dorsey’s account
best classic simpsons episodes disney plus jack dorsey twitter ceo

Cops have reportedly picked up a suspect who may have been involved in a hack over the summer that saw Twitter CEO Jack Dorsey’s own Twitter account compromised.

The suspect is thought to be a former member of a hacker group called the Chuckling Squad and is aged under 18 years old, according to a Motherboard report citing law enforcement and criminal sources. The arrest took place two weeks ago at an unspecified location but has only just come to light.

Read more
Twitter disables tweeting via SMS after CEO Jack Dorsey’s account was hacked
twitter auto crops improve with ai

Twitter announced on Wednesday that it would temporarily disable users’ ability to tweet via SMS. 

The official Twitter Support account made the announcement in a series of tweets, citing “vulnerabilities” that need to be addressed. 

Read more