The co-founder and chief executive of Twitter had his own account on the service briefly taken over by hackers.
A group referring to itself as the Chuckling Squad said it was behind the breach of Jack Dorsey's account.
The profile, which has more than four million followers, tweeted out a flurry of highly offensive and racist remarks for about 15 minutes.
Twitter said its own systems were not compromised, instead blaming an unnamed mobile operator.
"The phone number associated with the account was compromised due to a security oversight by the mobile provider," Twitter said in a statement.
"This allowed an unauthorised person to compose and send tweets via text message from the phone number. That issue is now resolved."
How did it happen?
A source at the company confirmed to the BBC that the hackers had used a technique known as "simswapping" (or "simjacking") in order to control Mr Dorsey's account. This is a technique whereby an existing phone number - in this case one associated with Mr Dorsey's account - is transferred to a new SIM card, usually after attackers trick or bribe customer support staff at a mobile provider. By taking control of the number, the attackers were able to post tweets via text message directly on to Mr Dorsey's Twitter account. While nowadays the overwhelming number of users use mobile apps to tweet, Twitter's early days were built around texting in updates - hence the character limit - and Twitter has kept this method, in part because of its use in developing countries with high data costs.What did the hackers post?
The offensive messages - some posted directly by the @jack account, and others retweeted from other accounts - used the n-word and made anti-Semitic comments referencing the Holocaust. One post suggested there was a bomb at the social media company's headquarters. A chat channel on Discord, a separate website, was apparently set up by the group to discuss and joke about the attack - but was quickly shut down. The Chuckling Squad has taken credit for a number of attacks on high-profile Twitter accounts recently, including beauty vlogger James Charles and an account belonging to YouTube personality Desmond Amofah, known as @Etika, who died earlier this year in an apparent suicide. While the security lapse appears to have happened outside the company, it is still an embarrassing incident for Twitter, a service which hosts the world's most powerful leaders. _____ Follow Dave Lee on Twitter @DaveLeeBBC Do you have more information about this or any other technology story? You can reach Dave directly and securely through encrypted messaging app Signal on: +1 (628) 400-7370DISCLAIMER: The Views, Comments, Opinions, Contributions and Statements made by Readers and Contributors on this platform do not necessarily represent the views or policy of Multimedia Group Limited.
Tags:
Latest Stories
-
Western Region: NDC youth wing embarks on phase 2 of ‘retail campaign’
22 mins -
Action Chapel International holds annual Impact Convention in November
23 mins -
Jana Foundation urges young women to take up leadership roles
28 mins -
All set for Joy FM Prayer Summit for Peace 2024
39 mins -
Managing Prediabetes with the Help of a Dietitian
58 mins -
Joy FM listeners criticise Achiase Commanding Officer’s election comment
1 hour -
Legal Aid Commission employees threaten strike over poor working conditions
1 hour -
Ghana ranked 7th globally as biggest beneficiary of World Bank funding
2 hours -
IMF board to disburse $360m to Ghana in December after third review
2 hours -
Former Bono Regional NPP organiser donates 13 motorbikes to 12 constituencies
2 hours -
Securities industry: Assets under management estimated at GH¢81.7bn in quarter 3, 2024
2 hours -
Gold Fields Ghana Foundation challenges graduates to maximise benefits of community apprenticeship programme
3 hours -
GBC accuses Deputy Information Minister Sylvester Tetteh of demolishing its bungalow illegally
3 hours -
Boost for education as government commissions 80 projects
4 hours -
NAPO commissions library to honour Atta-Mills’ memory
4 hours