{"id":1240143,"date":"2022-11-01T01:04:43","date_gmt":"2022-11-01T01:04:43","guid":{"rendered":"https:\/\/www.ghanamma.com\/2022\/11\/01\/twitters-verification-chaos-is-now-a-cybersecurity-problem\/"},"modified":"2022-11-01T01:04:43","modified_gmt":"2022-11-01T01:04:43","slug":"twitters-verification-chaos-is-now-a-cybersecurity-problem","status":"publish","type":"post","link":"https:\/\/www.ghanamma.com\/2022\/11\/01\/twitters-verification-chaos-is-now-a-cybersecurity-problem\/","title":{"rendered":"Twitter&#8217;s verification chaos is now a cybersecurity problem \u2022"},"content":{"rendered":"<p><\/p>\n<div>\n<p id=\"speakable-summary\">Cybercriminals are already capitalizing on Twitter\u2019s ongoing verification chaos by sending phishing emails designed to steal the passwords of unwitting users.<\/p>\n<p>The phishing email campaign, <a href=\"https:\/\/twitter.com\/zackwhittaker\/status\/1587188619000922112\" target=\"_blank\" rel=\"noopener\">seen by <\/a>, attempts to lure Twitter users into posting their username and password on an attacker\u2019s website disguised as a Twitter help form.<\/p>\n<p>The email is sent from a Gmail account, abd links to a Google Doc with another link to a Google Site, which lets users host web content. This is likely to create several layers of obfuscation to make it more difficult for Google to detect abuse using its automatic scanning tools. But the page itself contains an embedded frame from another site, hosted on a Russian web host Beget, which asks for the user\u2019s Twitter handle, password and phone number \u2014 enough to compromise accounts that don\u2019t use stronger two-factor authentication.<\/p>\n<p>Google took down the phishing site a short time after  alerted the company. A Google spokesperson told : \u201cConfirming we have taken down the links and accounts in question for violations of our program policies.\u201d<\/p>\n<div id=\"attachment_2434259\" style=\"width: 1034px\" class=\"wp-caption aligncenter\">\n<p id=\"caption-attachment-2434259\" class=\"wp-caption-text\">A screenshot of the phishing email designed to steal Twitter users\u2019 credentials. <b>Image Credits:<\/b> .<\/p>\n<\/div>\n<p>The campaign appears crude in nature, likely because it was quickly put together to take advantage of the recent news that Twitter will soon charge users monthly for premium features, including verification, as well as the reported possibility of taking away verified badges of Twitter users who don\u2019t pay.<\/p>\n<p>As of the time of writing, Twitter has yet to make a public decision about the future of its verification program, which launched in 2009 to confirm the authenticity of certain Twitter accounts, such as public figures, celebrities and governments. But it clearly hasn\u2019t stopped cybercriminals \u2014 even on the lower-skilled end \u2014 from taking advantage of the lack of clear information from Twitter since it went private this week following the close of Elon Musk\u2019s $44 billion takeover.<\/p>\n<p> also alerted Beget to the phishing pages, but did not immediately hear back. A spokesperson for Twitter did not immediately respond to a request for comment.<\/p>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are already capitalizing on Twitter\u2019s ongoing verification chaos by sending phishing emails designed to steal the passwords of unwitting users. The phishing email campaign, seen by , attempts to lure Twitter users into posting their username and password on an attacker\u2019s website disguised as a Twitter help form. The email is sent from a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1240145,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-1240143","post","type-post","status-publish","format-standard","has-post-thumbnail","category-celebrity-gossip"],"_links":{"self":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1240143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/comments?post=1240143"}],"version-history":[{"count":0,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1240143\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/media?parent=1240143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/categories?post=1240143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/tags?post=1240143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}