+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

Twitter contractors reportedly spied on the accounts of Beyoncé and other celebrities by creating fake help desk tickets

Jul 28, 2020, 05:23 IST
Business Insider
Photo by Kevin Mazur/Getty Images for Coachella
  • Twitter contractors in charge of monitoring account security and fraud improperly accessed data from the accounts of celebrities, including Beyoncé, Bloomberg reported Monday.
  • Former employees said Twitter's internal controls were so lax that contractors were able to see users' phone numbers, email addresses, and approximate locations by creating fake help desk requests, according to Bloomberg.
  • Twitter's security practices have come under intense scrutiny following a major hack of 130 prominent people and companies including Barack Obama, Joe Biden, Jeff Bezos, Elon Musk, Kanye West, Apple and Uber.
  • More than 1,000 employees and contractors had access to the internal tool at the core of the hack.
Advertisement

Twitter's lax internal policies allowed members of its security team to access the personal information of celebrity users, including Beyoncé, without their permission, Bloomberg reported Monday.

The security team, which is made up of 1,500 employees and contractors, has internal tools that allow it to see users' phone numbers, email addresses, and approximate location data in order to monitor accounts for fraud and content violations, the report said.

But widespread access to the tools and lenient rules around their use led some contractors to challenge each other to spy on celebrity accounts by submitting fake help desk tickets, former employees told Bloomberg.

Cognizant, the company that employed some of the contractors mentioned, did not immediately respond to Business Insider's request for comment.

In an email to Business Insider, a Twitter spokesperson said the company does not tolerate the misuse of internal tools, and that doing so could result in termination, but declined to comment on the specific cases reported by Bloomberg.

Advertisement

The degree of access and control employees and contractors granted has come under scrutiny in recent weeks after hackers gained control of internal tools and hijacked the accounts of 130 high-profile individuals and companies, allowing them to perpetuate a Bitcoin scam that likely netted them at least $120,000.

Twitter said the incident was the result of a "coordinated social engineering attack" — a technique that involves manipulating victims in order to obtain information about an organization — that allowed the hackers to gain access to internal tools only available to Twitter's support teams.

With that tool, hackers were able to see users' personal information, including phone numbers, email addresses, and in some cases, private messages, Twitter said in a blog post detailing what happened.

Last week, Reuters reported that more than 1,000 Twitter employees and contract workers had access to that same tool, making it difficult for the company to guard against hacks like this one.

Employees have raised similar concerns around Twitter's internal security measures on multiple occasions since at least 2015, including to its board of directors, but fixes were put on the back burner in order to prioritize engineering projects focused on making the company more money, according to Bloomberg.

Advertisement
You are subscribed to notifications!
Looks like you've blocked notifications!
Next Article