{"id":15196,"date":"2020-11-16T11:37:58","date_gmt":"2020-11-16T10:37:58","guid":{"rendered":"https:\/\/daniel.haxx.se\/blog\/?p=15196"},"modified":"2020-11-17T23:28:20","modified_gmt":"2020-11-17T22:28:20","slug":"i-lost-my-twitter-account","status":"publish","type":"post","link":"https:\/\/daniel.haxx.se\/blog\/2020\/11\/16\/i-lost-my-twitter-account\/","title":{"rendered":"I lost my twitter account"},"content":{"rendered":"\n<p>tldr: it&#8217;s back now!<\/p>\n\n\n\n<p>At 00:42 in the early morning of November 16 (my time, Central European Time), I received an email saying that &#8220;someone&#8221; logged into my twitter account <a href=\"https:\/\/twitter.com\/bagder\">@bagder<\/a> from a new device. The email said it was done from Stockholm, Sweden and it was &#8220;Chrome on Windows&#8221;. (I live Stockholm)<\/p>\n\n\n\n<p>I didn&#8217;t do it. I don&#8217;t normally use Windows and I typically don&#8217;t run Chrome. I didn&#8217;t react immediately on the email however, as I was debugging curl code at the moment it arrived. Just a few moments later I was forcibly logged out from my twitter sessions (using tweetdeck in my Firefox on Linux and on my phone).<\/p>\n\n\n\n<p>Whoa! What was that? I tried to login again in the browser tab, but Twitter claimed my password was invalid. Huh? Did I perhaps have the wrong password? I selected &#8220;restore my password&#8221; and then learned that Twitter doesn&#8217;t even know about my email anymore (in spite of having emailed me on it just minutes ago).<\/p>\n\n\n\n<p>At 00:50 I reported the issue to Twitter. At 00:51 I replied to their confirmation email and provided them with additional information, such as my phone number I have (had?) associated with my account.<\/p>\n\n\n\n<p>I&#8217;ve since followed up with two additional emails to Twitter with further details about this but I have yet to hear something from them. I cannot access my account.<\/p>\n\n\n\n<p><strong>November 17<\/strong>: (30 hours since it happened). The name of my account changed to Elon Musk (with a few funny unicode letters that only look similar to the Latin letters) and pushed for bitcoin scams.<\/p>\n\n\n\n<p>Also <a href=\"https:\/\/news.ycombinator.com\/item?id=25120918\">mentioned on hacker news<\/a> and <a href=\"https:\/\/www.reddit.com\/r\/programming\/comments\/jvor6q\/daniel_stenbergs_curl_twitter_account_compromised\/\">reddit<\/a>.<\/p>\n\n\n\n<p>At 20:56 on November 17 I received the email with the notice the account had been restored back to my email address and ownership.<\/p>\n\n\n\n<p>Left now are the very sad DM responses in my account from desperate and ruined people who cry out for help and mercy from the scammers after they&#8217;ve fallen for the scam and lost large sums of money.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How?<\/h2>\n\n\n\n<p>A lot of people ask me how this was done. The simple answer is that I don&#8217;t know. At. All. Maybe I will later on but right now, it all went down as described above and it does not tell how the attacker managed to perform this. Maybe I messed up somewhere? I don&#8217;t know and I refuse to speculate without having more information.<\/p>\n\n\n\n<p>I&#8217;m convinced I had 2fa enabled on the account, but I&#8217;m starting to doubt if perhaps I am mistaking myself?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why me?<\/h2>\n\n\n\n<p>Probably because I have a &#8220;verified&#8221; account (with a blue check-mark) with almost 24.000 followers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Other accounts<\/h2>\n\n\n\n<p>I have not found any attacks, take-overs or breaches in any other online accounts and I have no traces of anyone attacking my local computer or other accounts of mine with value. I don&#8217;t see any reason to be alarmed to suspect that source code or github project I&#8217;m involved with should be &#8220;in danger&#8221;.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Credits<\/h2>\n\n\n\n<p>Image by <a href=\"https:\/\/pixabay.com\/users\/jillwellington-334088\/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=2295434\">Jill Wellington<\/a> from <a href=\"https:\/\/pixabay.com\/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=2295434\">Pixabay<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>tldr: it&#8217;s back now! At 00:42 in the early morning of November 16 (my time, Central European Time), I received an email saying that &#8220;someone&#8221; logged into my twitter account @bagder from a new device. The email said it was done from Stockholm, Sweden and it was &#8220;Chrome on Windows&#8221;. (I live Stockholm) I didn&#8217;t &hellip; <a href=\"https:\/\/daniel.haxx.se\/blog\/2020\/11\/16\/i-lost-my-twitter-account\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">I lost my twitter account<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":5,"featured_media":15206,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[498],"class_list":["post-15196","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech","tag-twitter"],"_links":{"self":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/15196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/comments?post=15196"}],"version-history":[{"count":16,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/15196\/revisions"}],"predecessor-version":[{"id":15221,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/posts\/15196\/revisions\/15221"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media\/15206"}],"wp:attachment":[{"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/media?parent=15196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/categories?post=15196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/daniel.haxx.se\/blog\/wp-json\/wp\/v2\/tags?post=15196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}