This makes a lot more sense. I can't imagine Twitter isn't using some sort of phsyical 2FA like yubikeys which are virtually Phish proof if implemented well.
That being said, what was the employee's endgame here?
That being said, what was the employee's endgame here?
Especially if the real motivation is not the BTC scam, but the access to who knows how many DMs for possibly blackmail/propaganda down the line. (And not necessarily just DMs from the known compromised accounts, either.)
General disgruntlement maybe? Maybe they were simply pissed off and looking for a way to hurt the company.
Sometimes people behave very irrationally. In the most sensational cases that manifests as violence, but I think it might also manifest as acts of sabotage.