Entra ID & IdentityIncident TeardownsRetrospectives

The Twitter Hack (July 2020): Phone Spear-Phishing Against Internal Admin Tools

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

On July 15, 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple and others posted a cryptocurrency scam. Attackers had taken control of 130 accounts by compromising Twitter's own internal administrative tools.

How it happened

According to Twitter and later investigations, the attackers ran a phone spear-phishing campaign against a small number of Twitter employees. Posing as internal IT staff, they convinced employees to enter credentials on a phishing site, which also captured their MFA codes. With those credentials, the attackers accessed internal support tools that could change account settings, including email addresses, and then took over target accounts.

The scheme was carried out by a small group, including a teenager, and earned about $120,000 in bitcoin before it was shut down.

Why it mattered

  • Internal admin tools are high-value targets. They often have more power than any single account and less scrutiny than production systems.
  • Social engineering beats technical controls when MFA can be relayed in real time.
  • Too many employees had access to powerful tools.

New York's Department of Financial Services later reported that Twitter lacked a chief information security officer at the time and had inadequate access controls on internal tools.

Lessons for Microsoft 365 and Entra ID

  • Protect admin portals with phishing-resistant MFA — passkeys and FIDO2 keys don't work on phishing sites.
  • Just-in-time privileges with Privileged Identity Management.
  • Fewer people with access to admin tools.
  • Verify internal IT requests through known channels.

In hindsight

Phone-based social engineering of employees and help desks became one of the dominant attack techniques of the following years, used by groups such as Lapsus$ and Scattered Spider.

twitter hack 2020Twitter admin tool hack2020

More on this story