EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/criminal-hacking/twitter-bitcoin-hack-2020
194/430

File EL-0237HighResolvedCriminal Hacking / Social Engineering / Account Takeover

Twitter Bitcoin Scam Hack

Also filed as Twitter Account Takeover Scam · God Mode Hack

This incident involved the unauthorized takeover of high-profile accounts on Twitter to promote a Bitcoin scam. The attackers exploited internal administrative tools, demonstrating the severe security risks associated with employee access. The hack was a sophisticated social engineering operation rather than a technical code exploit.

  • #twitter
  • #bitcoin
  • #social-engineering
  • #account-takeover
  • #internal-tools
  • #scam
Notoriety8/10
Event
15 Jul 2020
Disclosed
15 Jul 2020
Target
Twitter
Actor
Graham Ivan Clark
Status
Resolved

01Summary

On July 15, 2020, a group of hackers, led by Graham Ivan Clark, successfully compromised the Twitter accounts of numerous prominent figures, including Joe Biden, Barack Obama, Elon Musk, and Bill Gates. The attackers used internal administrative tools, which they dubbed 'God Mode,' to post coordinated tweets promoting a fraudulent Bitcoin investment scheme. The method relied entirely on social engineering, where the perpetrators convinced a Twitter employee to grant them access to the internal admin panel. The hack highlighted critical vulnerabilities in Twitter's internal security protocols, specifically the ease with which a single compromised employee could destabilize global communication channels and financial trust.

02Background

The incident exposed the operational security weaknesses within major social media platforms. Prior to this, many platforms relied heavily on internal employee access for administrative functions, creating a single point of failure. The public nature of the hack immediately raised global concerns regarding the security of digital communication and the integrity of public figures' online presence.

03Key revelations

  1. 01The existence of 'God Mode' internal tools allowing full account control.
  2. 02The vulnerability of global communication channels to a single compromised employee.
  3. 03The ease with which high-profile accounts could be hijacked for financial fraud.

04Technical analysis

The attack did not involve zero-day exploits or complex malware. Instead, it was a classic social engineering attack. The perpetrators gained access by impersonating a co-worker and manipulating a Twitter employee into granting them credentials or access to the internal admin panel. This access allowed them to bypass standard authentication and directly manipulate the posting capabilities of high-profile accounts.

Attack vector
Social Engineering / Internal Access Compromise
Attack method
Account Takeover and Impersonation
Initial access
Social Engineering
Lateral movement
Internal Admin Panel Access
Exfiltration
Posting fraudulent content
Tool / malware
Internal Twitter Admin Tools ('God Mode')
Malware type
None (Social Engineering)

Vulnerabilities exploited

  • Weak Internal Access Controls
  • Insufficient Employee Vetting

MITRE ATT&CK techniques

  • T1566.001

05Threat actor

The group was primarily led by Graham Ivan Clark, who utilized social engineering tactics to gain unauthorized access. Their focus was purely financial, leveraging the credibility of high-profile accounts to execute a cryptocurrency scam.

Aliases

  • Mason Sheppard
  • Nima Fazeli

MITRE groups

  • T1566.001

Known members

  • Graham Ivan Clark

Attribution sources

  • Media Reports
  • Security Analysis

06Victims and impact

Additional victims

  • Joe Biden
  • Barack Obama
  • Elon Musk
  • Bill Gates
  • Jeff Bezos

Countries affected

  • United States

07Data exposed

Data types

  • Public Tweets
  • Account Credentials (Internal)

Notable documents

  • Fraudulent Tweets (Promoting Bitcoin Scam)

08Financial damage

The primary damage was reputational and financial loss to victims who followed the scam.

09Timeline

  1. 2020-07-15Hackers gain access to internal Twitter tools and post fraudulent tweets.
  2. 2020-07-15The scam is publicly exposed by media and security researchers.
  3. 2020-07-15Perpetrators are identified and subsequently charged.

10Key figures

  • Graham Ivan ClarkPrimary Hacker/PerpetratorAmericanConvicted and sentenced

11On the record

The hack revealed the existence of internal Twitter tools that allowed employees to take over any account, post tweets, and reset emails without a password.

Source Content, Describing the core vulnerability exposed by the incident.

12Reaction and fallout

Public reaction

The public reaction was one of alarm regarding digital security and the integrity of online communication. It led to widespread skepticism about online financial advice and increased scrutiny of social media platforms' internal security measures.

Political impact

The incident prompted immediate calls for stricter security protocols within major tech companies. It fueled public debate regarding the accountability of social media platforms when their tools are misused for fraud or political manipulation.

Geopolitical consequences

The hack served as a stark warning about the potential for foreign or domestic actors to destabilize public trust and financial markets using compromised high-profile accounts.

13Legal

The perpetrators were successfully identified and charged. The case resulted in criminal convictions, leading to a temporary, but significant, tightening of security protocols within the tech industry.

Prosecutions

  • Graham Ivan ClarkConvicted
    Charge
    Computer Fraud and Abuse Act violations
    Jurisdiction
    United States
    Sentence
    12 months in prison (details varied)

14Aftermath

Policy changes

  • Increased emphasis on Multi-Factor Authentication (MFA) for internal employee tools.
  • Stricter internal auditing and access logging for high-privilege accounts.

Regulatory changes

  • Increased regulatory focus on platform accountability for account misuse.

Security improvements

  • Mandatory separation of duties for administrative tasks.
  • Implementation of 'least privilege' access models for all employees.

15Significance and legacy

Significance

This incident is a landmark case study in social engineering and platform security. It demonstrated that the most critical vulnerability was not a technical flaw in the code, but a procedural flaw in human access control, proving that internal trust mechanisms could be exploited for massive financial fraud.

Legacy

The hack forced major tech companies to publicly acknowledge and overhaul their internal security architecture. It raised the industry standard for 'zero trust' principles, moving away from implicit trust based on employment status.

16Disclosure and media

Authentication
Media reporting and subsequent investigation

Media partners

  • The Washington Post
  • CNN
  • BBC

17Field notes

  1. 01The scam promised to double any Bitcoin sent to a specific wallet, a classic Ponzi scheme structure.
  2. 02The hack was widely cited as a prime example of how social engineering can bypass even sophisticated technical defenses.

18Resolution

The perpetrators were arrested, charged, and convicted, leading to the public disclosure of the security weaknesses and subsequent industry-wide security reviews.

19Sources

Official documents

  • Department of Justice Indictments (Related)

References

  1. [1]The Washington Post Reporting
  2. [2]Security Firm Analysis of Social Engineering
Fact sheetEL-0237

Dates

Event
15 Jul 2020
Started
15 Jul 2020
Ended
15 Jul 2020
Duration
1 days
Discovered
15 Jul 2020
Disclosed
15 Jul 2020
Resolved
15 Jul 2020
Ongoing
No

Target

Organisation
Twitter, Inc.
Type
Technology Company
Sector
Social Media
Country
United States

Actor

Name
Graham Ivan Clark
Type
Individual Hacker
Nationality
American
Affiliation
Twitter Internal Tools
Motivation
Financial gain through cryptocurrency scam
Attribution
High
Status
Convicted
Arrested
Yes
Convicted
Yes
Sentence
Sentenced to 12 months in prison (later reduced/modified)

Data

Sensitivity
Confidential
Published
Yes

Money

Crypto
Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.