It wouldn't surprise me if a lot of Twitter support people had access to these tools and that they often worked with larger (more valuable) accounts.
It also wouldn't surprise me if some employee had a bad 1:1 and then responded to a spear fish just because they were disgruntled. To take payment for it is particularly stupid.
Of course, could also be something more serious - but if it's really just the BTC piece and the people are dumb enough to talk to the press, it may not be a group of criminal masterminds.
I hope for the employee's sake they have communication that can help the feds catch the BTC group. Either way, an incredibly stupid thing to do on their part and I don't see a good ending for them.
If this turns out to be true, they'd be lucky not to go to prison.
If you're a sysadmin on a company email system, then you do technically have access to everyone's data on that system.
However, you're generally limited by company policy that you are not permitted to access/modify that data without direct authorisation, say from the employee themselves or from HR.
So, therefore, if you go and read the email of your boss, you're still in breach because you didn't have the authorisation.
The only item I can see here is fraud (impersonating the people whose accounts have been taken over), of which the mole would be complicit.
That's been exceptionally controversial, as it can turn contract breach into a federal criminal offence in the US.
Doesn't something similar happen with employer-provided accommodation and burglary laws?
People's accounts get hacked all the time. To help them recover is often a manual process, because the true owner of the account can become unclear. To be able to do that a support worker must be able to change the email address on an account, undo 2FA settings and make other changes because hackers will typically change the email address and add 2FA of their own phone as the first step in an account takeover.
Twitter is a disaster waiting to happen.
I can't think of any serious risk posed by 'the general population'. Maybe particular stocks would dip a bit?
I’m not sure what you’d charge them with?
I know HN doesn't believe in laws, but the rest of the world does, and they're the ones with prosecutors.
They could argue, with the advent of remote working getting more and more predominant, that they simply left their computer unattended for a second while logged in.
Beyond that, they could argue they simply clicked on a link and something might have happened they aren't aware of. Or that they didn't know what running that one executable would do.
Parting shot: unnecessary, obnoxious. -1
Net: 0
People seem to assume everyone takes tweets at face value and won't do a double take when it doesn't sound like something they would normally say.
Even here there was plenty of people on HN who were claiming outlandish possibilities while it was happening.
Poorly executed, frankly. The tweet just wreaked of spam.
e.g., Vietnam is a livable place and GDP per capita is ~$2600. That'd get you a very modest living. GDP/capita is also up 2x from 10 years ago and 10x from 20 years ago. You could maybe squeak out 20 years with very modest living and few unplanned expenses and assuming the economy and thus cost of living doesn't grow tremendously (like it likely will).
Somalia would give you a little more value for your money. But I think if someone suddenly had that much money in Somalia, they'd probably be getting out of Somalia or hoping nobody found out.
Almost anything else I can think of would require either (a) substansal amount of starting cash (for example trying to crash Tesla's stock price), or (b) be almost impossible to pull off without getting caught (blackmail, or again stock manipulation if you do it in a big enough way to make some decent money).
In terms of risk/reward, assuming someone found some easy trick and wanted to cash out ASAP, this feels like the best option.
Alternatively, is it possible they bought options on twitter itself? It’s down 4% in after-hours (which is less than I expected, but still enough delta to make some cash).
On the other hand, $1M in BTC might do the trick. Interesting thought experiment...
And/or they just thought it couldn't be traced back to them.
And you're also making the assumption that the accomplice thought about it rationally. All the attacker has to do is find someone who doesn't realize that they will get caught.
If that was the case they could only deal with bitcoin. Blackmailing with bitcoin may be smarter but maybe they figured that would be investigated more or treated more harshly? They could have released fake financial tweets and shorted the market - but that still would be investigated much faster.
I'm sure the 100k or whatever they got isn't as much as it could be - but for a random dude who paid 10k to a disgruntled employee it is pretty good.
I don't think there is something super nefarious involved. Probably some unpaid intern in a third world country where Twitter outsources tech support.
If the attackers had a big short position in TWTR, they may have made a lot more money than they received from BTC.
Also, if you had Elon tweet that, I am not sure if the price will go up or down like you expect. :)