X / Twitter the hacker drama▊
Twitter’s real security record isn’t a policy debate — it’s a rap sheet. In 2009 a bored Frenchman calling himself Hacker Croll guessed his way into a Twitter employee’s email, walked out with the administrative password and around 300 confidential internal documents, and mailed them to a blog; the FTC put the company under a twenty-year consent order. Not much changed. Over the next decade the platform kept losing its own keys: a black market in one-letter handles extracted by social-engineering PayPal and GoDaddy; the CEO’s own account SIM-swapped and made to tweet bomb threats; and in July 2020 a seventeen-year-old from Tampa talked his way into the internal “God-mode” admin panel and made Obama, Biden, Musk, Gates, and Apple all promise to double your Bitcoin. Twitter hired the legendary Mudge to clean it up — then fired him, and got a Senate whistleblower for the trouble. This file is the break-ins. The censorship-and-disinformation saga is a different kind of capture, and it lives at evilrobots.lol.
We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.
Twitter Support (@TwitterSupport), the night of July 15, 2020, as roughly 130 of the most famous accounts on earth were tweeting a Bitcoin scam. The company’s follow-up conceded the attackers reached its internal “agent” tools. Twitter incident report, July 2020
- WHO
- Twitter, Inc. (now X Corp) — and the decade of break-ins that kept proving the front door was a phone call away FACT
- FIRST BLOOD
- 2009: “Hacker Croll” reaches an employee’s email, then the admin panel, and leaks ~300 internal documents to TechCrunch; the FTC imposes a 20-year order over the security lapses FACT
- THE HANDLE WARS
- A black market in rare handles run on social engineering — the @N extortion (2014) — and SIM-swapping that took over CEO Jack Dorsey’s own account in 2019 FACT
- THE BIG ONE
- Jul 15, 2020: phone spear-phishing gets into the internal admin tools; ~130 accounts hijacked, ~$118K in bitcoin taken; Graham Ivan Clark, 17, convicted FACT
- THE CLEANUP
- Mudge (Peiter Zatko) hired Nov 2020 to fix it, fired Jan 2022, then filed a whistleblower disclosure alleging the failures were structural ATTRIBUTED
- STATUS
- REPEAT OFFENDER — same failure for a decade: too many hands on the master keys, and staff who could be talked out of them
The moral of the Twitter security story is boringly consistent: the platform was almost never broken by exotic exploits. It was broken by someone picking up a phone. A guessed password, a lied-to support rep, a spoofed carrier, a spear-phished employee — the same human hole, reopened every few years, all the way up to the day a teenager owned the accounts of two U.S. presidents at once. This file tracks that hole. For the parallel fight over what Twitter allowed to be said — the moderation, the “Twitter Files,” the disinformation-scoring apparatus — that’s a capture story, and it’s filed at evilrobots.lol.
the drama timeline
ACT I — HACKER CROLL AND THE TWENTY-YEAR LEASH (2009–2011)
The platform’s first famous breach isn’t a hack so much as a series of good guesses and polite requests — and it ends with a federal consent order the company would spend a decade quietly violating in spirit.
-
JAN 2009
35 accounts, one weak password
An 18-year-old using the handle “GMZ” notices a Twitter support account and, per his own account, uses a dictionary tool to guess its password — landing on “happiness.” That account had access to an internal admin panel. Within reach: the verified accounts of Barack Obama, Britney Spears, Fox News, and dozens more — 33 in all — handed out to others who defaced them. The tell of the decade to come: the break-in wasn’t the network. It was one over-privileged support tool guarding the whole platform behind a guessable word.
-
APR–JUL 2009
Hacker Croll mails the company to a blog
A French intruder calling himself Hacker Croll works into the personal email of a Twitter employee, pivots to the company’s Google Apps and administrative accounts, and lifts roughly 300 confidential internal documents — financial projections, meeting notes, executive contracts. He mails a trove to TechCrunch, which publishes a selection that July. Twitter’s crown jewels were exfiltrated not by malware but by resetting a password to a Gmail account and reading the founders’ mail.
-
2010–2011
The FTC puts Twitter on a 20-year leash
The Federal Trade Commission charges that Twitter’s lax controls — too many employees with administrative power, no reasonable safeguards on that power — let attackers seize the accounts and deceived users who’d been promised their information was protected. Twitter settles: barred for twenty years from misrepresenting the privacy and security of user data, and required to stand up an independently audited security program. It is one of the first data-security consent orders of its kind. The pattern it was meant to fix — over-privileged internal tooling — is the exact hole a teenager walks through in 2020.
ACT II — THE HANDLE WARS (2014–2019)
Once a Twitter name is worth money, the attack surface becomes the phone lines of every company that can reset a password — and eventually the CEO’s own number.
-
JAN 2014
“I’ll ransom your domain for @N”
Developer Naoki Hiroshima owns the coveted one-letter handle @N — he says he’d been offered $50,000 for it. An attacker calls PayPal and, per Hiroshima, is read the last four digits of his card; uses that to talk GoDaddy into surrendering his domain; then holds the domain (and the email on it) hostage until Hiroshima hands over @N. No exploit, no malware — just two phone calls to two help desks. It becomes the canonical story of the handle black market and of why “account security” means the security of every vendor that can reset your account.
-
2018–2019
SIM-swapping industrializes the theft
The handle-and-crypto black market moves to SIM-swapping — bribing or tricking a carrier into porting a target’s number to the attacker’s SIM, defeating SMS two-factor and every account chained to that number. The scene, largely teenagers out of the OGUsers forum, turns it into a conveyor belt (see the file on Joel Ortiz, the first person imprisoned for it). Twitter accounts — especially rare ones — are a prime target, because for years the platform tied account recovery to a phone number.
-
AUG 30, 2019
The CEO gets SIM-swapped
For about twenty minutes, @jack — the account of Twitter’s own co-founder and CEO, Jack Dorsey — spews racial slurs, antisemitic content, and a bomb threat against Twitter’s offices. A crew calling itself the Chuckling Squad had SIM-swapped his phone number and abused the old “tweet-by-text” feature, which let a text message post to the account with no app login at all. If the man who runs the platform can’t keep his own handle, the FTC’s 2011 warning has plainly gone unheeded.
ACT III — GOD MODE (JULY 2020)
Every earlier lesson ignored, all at once: over-privileged internal tools, staff who can be talked into anything, and the most valuable accounts on the internet a single admin panel away.
-
JUL 15, 2020
Obama, Biden, Musk, Gates — all doubling your Bitcoin
Attackers run a phone spear-phishing campaign against Twitter staff, reach the internal “agent” admin tools that can control any account, and take over roughly 130 accounts — Obama, Biden, Bloomberg, Bezos, Gates, Musk, Kanye West, Apple. Around 45 tweet a “send $1,000 in bitcoin, get $2,000 back” scam that nets about $118,000 in a few hours. Twitter’s only fix mid-crisis is to lock every verified account on the platform. The ringleader, “Kirk,” turns out to be Graham Ivan Clark — 17, from Tampa, out of the SIM-swap/OGUsers scene — who pleads guilty to 30 charges and takes a three-year sentence; co-defendants including Joseph “PlugwalkJoe” O’Connor are charged too.
ACT IV — MUDGE COMES TO CLEAN UP, THEN BLOWS THE WHISTLE (2020–2022)
Twitter hires the most respected security name it can find, ignores him for eighteen months, fires him — and hands him a reason to put the whole story under oath.
-
NOV 2020
Enter Mudge
Bruised by the Bitcoin hack, Twitter hires Peiter “Mudge” Zatko — the l0pht legend who told the Senate in 1998 he could take down the internet in 30 minutes, later at DARPA, Google, and Stripe — as head of security, reporting directly to Dorsey. He is, on paper, exactly the right person to close the decade-old hole.
-
JAN–SEP 2022
Fired, then sworn in
CEO Parag Agrawal fires Zatko in January 2022. That July he files an 84-page whistleblower disclosure with Congress, the SEC, and the FTC, and testifies to the Senate: thousands of employees still had needless access to live systems, the company couldn’t reliably count its own bots and spam, and leadership was “misleading the public, lawmakers, regulators and even its own board.” Twitter calls him a disgruntled ex-executive pushing a “false narrative.” His bot claims become Elon Musk’s lever to try to escape the $44B acquisition on the theory the platform undercounted fakes — the same accounting Zatko said never existed. Musk closes anyway that October. The security file, at least, was inherited exactly as broken as Mudge said.
both sides, on the record
The case: for more than a decade Twitter was breached the same way — not through clever exploits but through over-privileged internal tools and staff who could be talked, phished, or SIM-swapped out of the keys. A guessed password in 2009, a lied-to help desk in 2014, a spoofed carrier in 2019, a spear-phished employee in 2020. The FTC ordered it fixed in 2011; nine years later a 17-year-old owned the accounts of two sitting-and-future presidents at the same time. When the company finally hired a security chief equal to the problem, it sidelined and fired him — and his sworn account said the rot was structural and known.
The defense, as stated: social engineering defeats nearly every large company, and the 2020 attackers used a genuinely sophisticated, targeted phone-phishing operation — Twitter detected it within hours, locked the entire verified tier to stop the bleeding, and cooperated with a federal investigation that produced arrests within two weeks. It did move account recovery off SMS and hire a marquee security leader. And Zatko’s allegations are his — Twitter flatly denies them and calls his exit performance-related; a whistleblower’s narrative is not an adjudicated finding.
The honest limits: Zatko’s claims are contested and unproven; “Hacker Croll” is a pseudonym and the 2009 details come from reporting and the FTC complaint, not a trial; the bitcoin figure is an approximation from the blockchain and reporting. The court-proven core is narrow and damning on its own: the 2020 intrusion happened, through Twitter’s own admin tools, and a teenager was convicted for it.
YOU DECIDE
Strip out the celebrity names and every Twitter break-in is the same sentence: someone got a human to hand over access that should never have been reachable by a human alone. Hacker Croll read the founders’ email. A social engineer ransomed a domain for a letter. A carrier gave away the CEO’s phone number. A teenager phoned his way to God mode. The FTC saw it in 2011 and wrote it down; the company signed the order and kept the hole. The archive’s note is simple: the exploit was never the network. It was always the org chart — too many keys, too many hands, and a help desk that wanted to be helpful.
The network was never the weak point. The people with the keys were.
evidence locker
PRIMARY / GOVERNMENT & FIRST-PARTY RECORD
FTC — final settlement, “Twitter, Inc.” FACT — the 20-year order over the 2009 security failures and the admin-access breach. (EDGAR-style block on scrapers; loads in any browser.)
ftc.gov — final settlement with Twitter
Naoki Hiroshima — “How I Lost My $50,000 Twitter Username” FACT — the victim’s own first-party account of the 2014 @N extortion via PayPal and GoDaddy social engineering.
medium.com/@N — the @N extortion
Twitter — “An update on our security incident” FACT — the company’s own July 2020 incident report: the coordinated social-engineering attack and the reach into internal admin tools.
blog.twitter.com — the 2020 incident report
Senate Judiciary Committee — testimony of Peiter “Mudge” Zatko ATTRIBUTED — the whistleblower’s sworn 2022 statement on structural security failures. His claims; Twitter denies them.
judiciary.senate.gov — Zatko testimony
REPORTING
Wired — “Weak Password Brings ‘Happiness’ to Twitter Hacker” FACT — the January 2009 admin-tool breach: the guessed “happiness” password and the hijacked verified accounts.
wired.com — the 2009 “happiness” breach
TechCrunch — the FTC settlement & the Hacker Croll document leak FACT — Croll’s route through an employee’s email to ~300 internal documents.
techcrunch.com — Croll & the FTC
CNBC — “Hack of Jack Dorsey’s Twitter account highlights SIM swapping” FACT — the 2019 SIM-swap of @jack by the Chuckling Squad.
cnbc.com — @jack SIM-swapped
The Register — “Peiter Zatko is Twitter’s new security chief” FACT — Mudge hired Nov 2020 in the wake of the Bitcoin hack.
theregister.com — Mudge hired
CONTEXT & CROSS-LINKS
evilrobots.lol — Hamilton 68 & the disinformation apparatus CROSS-LINK — the OTHER Twitter story: moderation, the “Twitter Files,” and the disinfo-scoring machine. That’s a capture file, and it lives on the sister site.
evilrobots.lol/profiles/hamilton-68/
The standard. This file documents Twitter/X’s security and hacker-drama record from the public and first-party record: the FTC consent order; the 2009 TechCrunch document leak; Naoki Hiroshima’s own account of the 2014 @N extortion; reporting on the 2019 SIM-swap of Jack Dorsey’s account; Twitter’s own July 2020 incident report and the court record of Graham Ivan Clark’s conviction; and reporting on Mudge’s hiring. Stated as fact: the breaches, the FTC order, the extortion, the SIM-swaps, the 2020 intrusion via Twitter’s admin tools, and Clark’s conviction. Attributed and never adopted: Peiter Zatko’s whistleblower allegations, which Twitter denies and which no court has adjudicated. “Hacker Croll” and “Kirk” are handles; no identity is asserted beyond what was publicly reported and, for Clark, proven in court. The content-moderation and disinformation saga — the “Twitter Files,” Hamilton 68, the scoring apparatus — is a capture story and is filed at evilrobots.lol, cross-linked, not restated here. If a line here couldn’t survive scrutiny, it wouldn’t be on the page.