At 4:17 PM ET on July 15, 2020, a tweet appeared from @Apple: "We are giving back to our community. We support Bitcoin and we believe you should too! All Bitcoin sent to our address below will be sent back doubled!" Thirteen minutes later, the same message appeared from @Uber. Then @Barack Obama. Then @Joe Biden, @Mike Bloomberg, @Elon Musk, @Bill Gates, @Kanye West, @Jeff Bezos, @Warren Buffett. Then the official accounts of @Apple, @Uber, @CashApp.
Twitter's internal tools had been compromised. A 17-year-old in Tampa, Florida, working with a network of associates from the SIM-swapping underground, had convinced Twitter employees to hand over access to those tools with a phone call. The subsequent cryptocurrency scam netted approximately $120,000. The security failure was considerably more consequential than the crime.
The Attack: Social Engineering Twitter's Internal Tools
The attackers did not exploit a software vulnerability in Twitter's platform. They called Twitter employees. Using information gathered from LinkedIn about Twitter's internal structure, they identified employees with access to the internal admin tool - "@Admin" or "God Mode" in internal parlance - that allowed privileged operations on any Twitter account.
The initial calls targeted Twitter employees who were not themselves admins, using a vishing (voice phishing) technique: the callers posed as Twitter IT department workers performing a security audit and directed employees to a fake internal website that harvested their VPN credentials. Once inside the corporate VPN, they had access to internal tools. A second stage of calls to employees with higher privileges eventually obtained access to the specific admin panel that allowed bypassing two-factor authentication and taking over accounts.
Once they controlled the admin panel, the attackers locked out account owners, changed the email addresses associated with accounts, and disabled two-factor authentication. This gave them complete control of each targeted account. They could have read private messages, exfiltrated contact lists, or posted anything they chose. They chose to run a Bitcoin scam.
The Suspects
Within weeks, investigative journalists at Motherboard, the New York Times, and independent researchers had developed significant intelligence on the attackers. The primary architect appeared to be a British national known online as "Kirk" - who had obtained the Twitter admin access and was selling account takeovers for cryptocurrency. Kirk used the access to sell "OG" Twitter handles (short, desirable usernames) to buyers in the SIM-swapping underground at prices ranging from $1,500 to $10,000.
Three individuals were arrested. Graham Ivan Clark, 17, of Tampa was identified as the primary actor - "Kirk" - and was charged as an adult under Florida law with 30 felony counts. He accepted a plea deal and was sentenced to three years in a juvenile facility followed by three years probation. Mason Sheppard (UK) and Nima Fazeli (US) were charged with federal crimes for their roles in selling the stolen accounts. Clark was 17 at the time of the hack.
The Bitcoin Scam
The cryptocurrency addresses posted in the fake tweets received approximately 400 transactions totaling around $120,000 in Bitcoin before Twitter could remove the tweets - a process that took about an hour. Twitter temporarily disabled the ability of verified accounts to tweet while it investigated.
The scam's relatively small take was partly due to the speed of Twitter's response and partly due to widespread public skepticism - many users immediately identified the posts as fraudulent and began publicly flagging them. The attackers were constrained by the bluntness of a mass-broadcast Bitcoin address: there was no way to customize the scam for individual high-net-worth targets, no way to escalate pressure, and no way to prevent victims from comparing notes publicly in real time on the same platform being used for the fraud.
Twitter's Internal Access Controls
The hack revealed that Twitter's internal admin tool had minimal controls on who could access it or audit its use. A support employee with the right credentials could reset an account's email address, disable two-factor authentication, and change the password - effectively taking over any account. The access wasn't segmented by the account's sensitivity or the employee's role.
Twitter had known this was a risk. Internal documentation surfaced in a whistleblower complaint (from former head of security Peiter "Mudge" Zatko in 2022) suggested that Twitter's security culture had longstanding problems: inadequate access controls, limited logging of admin tool use, and a pattern of prioritizing growth over security engineering. The 2020 hack was not the first misuse of Twitter's internal tools - similar tools had been abused by employees and contractors in prior years.
The Federal Trade Commission's existing consent decree with Twitter - from a 2011 settlement over a prior privacy incident - required Twitter to implement adequate information security controls. The FTC opened a new investigation. Twitter eventually paid a $150 million fine in 2022 for separately violating the consent decree by using phone numbers collected for two-factor authentication for targeted advertising - a different violation, but in the context of a pattern of security and privacy governance failures.
The Broader Context: The COM Underground
Graham Clark was connected to the same English-speaking cybercriminal underground as Scattered Spider and LAPSUS$ - the network of young hackers who communicated over Discord, traded SIM swaps and OG account handles on OGUsers.com, and developed increasingly sophisticated social engineering techniques. Clark had been active in this community for years before the Twitter hack.
His path to Twitter's internal tools followed the same basic pattern as the SIM swapping operations that had been ongoing for years: identify an employee, find their phone number, call them. The difference was calling Twitter employees rather than T-Mobile carrier stores, and the payload being admin panel access rather than a ported phone number. The underlying technique - voice phishing against an employee with access to a privileged internal system - was the same technique used in subsequent years by Scattered Spider against MGM, Caesars, and Uber.