Twitter alarms users with messages that resembled phishing emails
Full article585 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
At least everyone was on guard enough to be suspicious of the Twitter emails.
Twitter sparked a panic among some users that they were the subjects of a phishing attack in what was instead an accidental mass email.
The message sent to some Twitter users went out Thursday, asking them to confirm their email addresses by clicking on a button. To many of those users who commented about it on the social media platform, it smelled like a possible phishing attempt.
Twitter clarified what had happened later that same evening.
“Some of you may have recently received an email to ‘confirm your Twitter account’ that you weren’t expecting,” the company said. “These were sent by mistake and we’re sorry it happened. If you received one of these emails, you don’t need to confirm your account and you can disregard the message.”
In the cybersecurity sphere, Twitter usually gains the most attention for its efforts to combat online misinformation, or criticisms about how it’s handling that battle.
But there’s a significant history of attackers making Twitter-based hacking attempts. One of last year’s biggest security incidents came last summer, when scammers took over high-profile Twitter accounts from the likes of then-presidential candidate Joe Biden via a phone spearphishing attack to advance a cryptocurrency scheme.
A Twitter glitch has caused a data breach before, too, prompting European regulators to fine the company for not adequately disclosing an incident in which private tweets were made public.
This time, though, it was apparently a harmless false alarm. And some cybersecurity experts thought the public reaction on the platform — cautioning against clicking on the confirmation button — was encouraging.
“Great instincts from everyone though who mentioned not to click before learning more and suspect phishing as the email was definitely a pretext a cyber criminal would use!” tweeted Rachel Tobac, CEO of SocialProof.
That random Twitter confirmation email was a bug and not phishing. Great instincts from everyone though who mentioned not to click before learning more and suspect phishing as the email was definitely a pretext a cyber criminal would use! https://t.co/cBnxppAhHQ
— Rachel Tobac (@RachelTobac) April 23, 2021
Twitter has a website page devoted to how to detect whether users have received an authentic email from the company.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/twitter-phishing-confirm-email-mistake/