About Us | Contact Us
View Cart

The Coveted Twitter Account: A Cautionary Tale

By Vigilize | Wednesday, January 29, 2014 - Leave a Comment

A man’s story of how a hacker stole his twitter account using social engineering.

 

We all know how important it is to take security seriously. Thankfully, few of us have experienced the stress of actually having an account hacked or held for ransom. Naoki Hiroshima was not so lucky.

As he recounts in the original article, he once held the coveted Twitter account handle “@N.” On January 20 of this year, he was made aware of a hacker attempting to steal the handle. It began as a text message from PayPal about a validation code which he did not initiate. He later received a message from GoDaddy that his account settings had been changed.

The hacker then proceeded to email Naoki, informing him that he was holding his websites hostage. If he did not change his handle, he would make sure the domains would never again see the light of day. “I would also like to inform you that your GoDaddy domains are in my possession, one fake purchase and they can be repossessed by godaddy and never seen again.”

Naoki’s experience with attempting to right this issue with GoDaddy were less than successful. “My claim was refused because I am not the “current registrant.” GoDaddy asked the attacker if it was OK to change account information, while they didn’t bother asking me if it was OK when the attacker did it.”

After the Twitter handle switch had been made, the hacker divulged the truth of how he was able to obtain the information to hack into Naoki’s GoDaddy account through social engineering. “I called paypal and used some very simple engineering tactics to obtain the last four of your card. I called godaddy and told them I had lost the card but I remembered the last four, the agent then allowed me to try a range of numbers.”

To avoid this situation from happening, Naoki suggests not using a custom domain email address and instead sticking with something like @gmail.com for logins. He also stresses the importance of two-factor authentication which he credits for keeping the hacker from gaining access to his PayPal account.


Original article by Naoki Hiroshima.
Read the full story here.

Latest News
    PRESS RELEASE – FOR IMMEDIATE RELEASE SERVICE NEWS Dateline: Dayton, IN, June 22, 2022 We are proud to announce that infotex will now be supporting Endpoint Detection and Response (XDR/MDR)! We can manage/monitor solutions you already have or offer one as part of our service while still maintaining a segregated response posture. In recent years […]
    Over 85 percent of surveyed companies report having no  centralized monitoring of networked industrial devices… An article review. If you are involved in IT within your organization, you’re probably aware of the importance of being able to monitor relevant activity from your networked devices, especially if your organization is involved in healthcare, finance, or government.  […]
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Check out posters.infotex.com for the whole collection! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around […]
    We always strive to bring you the best content that we possibly can. Your opinion on any content, presentation, service, or anything else you have received from us is important! Please click the button below to let us know how we are doing!  
    What to Expect in an Annual Information Security Report to the Board Webinar-Movie Information security ranks as a top risk to financial institutions, both in terms of likelihood and overall impact. It is important that boards receive annual comprehensive reporting from management about the information security risks and incidents, and the actions taken to address […]
    The Five Precepts of IT Vendor Management Webinar-Movie We’re going back to basics on Vendor Management. This webinar will give you a training tool to help out that new person that is starting to take on the gargantuan task that is Vendor Management.
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Check out posters.infotex.com for the whole collection! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around […]
    The joint cybersecurity advisory includes the 15 most exploited vulnerabilities reported in 2021… An article review.  While a lot of attention is focused on previously undisclosed or “zero day” attacks, some of the most likely attack vectors are vulnerabilities that have been widely known for weeks or even months.  That’s according to a new joint […]
    Threats are changing, EDR can help us adapt . . . Today’s advanced persistent threat (APT) understands that the IT landscape has changed. In the post-COVID age, more and more organizations have adopted some form of work from home.  While WFH offers many conveniences, it also imparts increased risks. BitSight conducted a 2021 study of […]
    A new way of helping people “read” new guidance… Look for more in the future! To save you time, we are proud to present “Adam Reads” . . . recorded versions of our Guidance Summaries! Below you can find an embedded player for the audio file. If you are having issues with that working, you […]