How social engineering hacked the CIA director, took over the Twitter accounts of Elon Musk and Joe Biden, and stole half a billion dollars.
Even a schoolboy can hack the CIA director.
Let's start with a story that could easily be the basis for a feature film. With a title like "Hackers vs. Spies"—though it wouldn't be an action thriller, as one might expect, but rather a satirical comedy.
In October 2015, hackers from the group Crackas With Attitude used social engineering to gain access to CIA Director John Brennan's personal AOL email account. The hack was followed by a phone interview with the New York Post by one of the group's members, during which he described himself as an American schoolboy.
Although the CIA director's email account was personal, it revealed many interesting items related to his work: specifically, the Social Security numbers (SSNs) and other personal information of more than a dozen high-ranking US intelligence officials, as well as a 47-page application for access to top secret information from John Brennan himself.
In November of that same 2015, the story continued: this time, the personal AOL email accounts of another high-ranking official, FBI Deputy Director Mark Giuliano, and his wife, were hacked. This time, the hackers' catch, which they made public, included the names, email addresses, and phone numbers of 3,500 employees of various US law enforcement agencies.
A couple of months later, in January 2016, the same hackers gained access to numerous personal accounts of US Director of National Intelligence James Clapper. Finally, in February 2016, they publicly released the data of 9,000 US Department of Homeland Security and 20,000 FBI employees, which, according to the hackers themselves, they obtained by hacking the US Department of Justice.
Also in February 2016, one of the hackers was arrested. He indeed turned out to be a schoolboy (though not American, but British) named Kane Gamble. Ultimately, the young hacker, aka Cracka, who was only 15 at the time of the crime, was named the group's leader and sentenced in the UK to two years in prison (of which he served eight months), and was banned from using the internet for the same period (and he had to serve that sentence in full). A few months later, two other older members of Crackas With Attitude were arrested in the US: Andrew Otto Boggs, 23, received two years in an American prison, and Justin Gray Liverman, 25, received a full five years.
As was revealed in court, young Gamble managed to successfully pose as the CIA director for over six months—from June 2015 to February 2016—and use his guise to trick call center and hotline employees into giving up passwords. With these passwords, the group ultimately gained access to highly classified documents related to intelligence operations in Afghanistan and Iran. And who knows if the hackers would have been caught at all if they hadn't simultaneously made a mockery of the CIA director, the FBI deputy director, and the US Director of National Intelligence?
Hacking the Twitter accounts of Biden, Musk, Obama, Gates, and many others
The next incident occurred on July 15, 2020. A bunch of Twitter accounts began spreading similar messages: "All bitcoins sent to the address below will be returned double!" "If you send $1,000, I'll give you $2,000 back. I'm only doing this for the next 30 minutes." Naturally, these messages were sent on behalf of famous people and major companies. It's a classic Bitcoin scam, and there wouldn't be anything interesting about it if not for one important detail: all these accounts were genuine—they actually belonged to famous people and major companies.
First, the scam messages began appearing on Twitter accounts directly related to cryptocurrency: the giveaway was announced by Binance crypto exchange founder Changpeng Zhao, along with accounts from several other crypto exchanges, including Coinbase, and the crypto news site Coindesk. But things didn't stop there; one after another, more and more accounts belonging to businessmen, celebrities, politicians, and companies began joining this fraudulent bacchanalia: Apple, Uber, Barack Obama, Elon Musk, Kim Kardashian, Bill Gates, Joe Biden (who was not yet US President at the time), Jeff Bezos, Kanye West, and so on.
In the few hours Twitter spent investigating the root of the problem, the hackers managed to collect over $100,000—a considerable sum, but certainly nothing compared to the damage to the social network's reputation. It quickly became clear that the hackers had gained access to Twitter's internal account management system, and it was initially assumed that an insider had helped them do so.
However, things turned out differently. The hackers were quickly found and arrested, and the leader of the hacking group was once again a schoolboy—this time, an American: seventeen-year-old (at the time of the hack) Graham Ivan Clark. He ultimately received three years in prison and an additional three years of probation. But most importantly, the investigation revealed that the hackers had not relied on an insider. Instead, they used a mixture of social engineering and phishing to gain access to the system from Twitter employees.
First, they conducted research on LinkedIn, which identified employees who likely had access to the account management system. Afterwards, they used LinkedIn's recruiter feature to obtain the employees' contact information, including cell phone numbers. They then called Twitter employees, posing as colleagues, and, using the previously collected data, convinced them to visit a phishing site mimicking the login page for Twitter's internal systems. This way, they obtained passwords and two-factor authentication codes, which they used to log into Twitter's account management system and take over dozens of accounts with millions of followers.
Again, who knows if the hackers would have been caught if they hadn't targeted the accounts of half of the world's top ten richest people, along with other famous figures, and, most importantly, the Twitter accounts of a former US president and then-presidential candidate.
The Sky Mavis Heist of Half a Billion Dollars
And finally, the third story took place in 2022. Sky Mavis, creator of the NFT game Axie Infinity, played a key role. Without going into the details of the gameplay, suffice it to say that this game allows users to earn cryptocurrency. At one point, some residents of Southeast Asia even used it as a job. At its peak, the game's daily audience reached 2.7 million players, with revenue reaching $215 million per week.
However, in March 2022, even before the well-known events in the cryptocurrency market began, Sky Mavis suffered a serious setback. During an attack on the Ronin blockchain platform, which is the core of all cryptocurrency activity at Axie Infinity, hackers managed to steal 173,600 ETH and 25.5 million USDC from the company's accounts—approximately $540 million at the exchange rate at the time of the attack. In July of that year, details of the theft emerged. It turned out that hackers, posing as a fake company, had been contacting Sky Mavis employees on LinkedIn and inviting them to interview for positions. This led them to one of Sky Mavis's senior engineers, who, after several rounds of interviews, received a very tempting job offer. The fake offer was sent in an infected PDF file. Using this, the hackers eventually gained access to the company's internal network.
Then it was a matter of technique: using access to the corporate network, the hackers were able to obtain the necessary number of private keys to confirm transactions and successfully withdraw the cryptocurrency. They laundered the stolen funds through a complex scheme involving two crypto mixers, approximately 12,000 intermediate crypto wallets, and conversion to BTC, followed by cashing out via Bitcoin.
According to analysts assisting US law enforcement with the attack, the North Korean group Lazarus was involved in the hack. Only a small portion of the stolen cryptocurrency was recovered—about 10% in nominal coins, or about 5% in dollars. The cryptocurrency market experienced a significant decline in the six months between the theft and the investigation's conclusion, causing the Ethereum price to plummet.

Spain
Portugal


