Curriculum·G704 Community Moderation·about 32 min

Social engineering of the people who hold the keys

By the end of this lesson you can

  • State what happened in the Twitter compromise of 15 July 2020, how access was obtained, how many accounts were used, and who was charged
  • Explain why the people who administer a platform are its most valuable target, and why a phone call defeats controls that a login attack cannot
  • Compute what the scam took against the reach it had, and read what the ratio says about why the attackers were caught
  • Write a moderator protocol that assumes every moderator will be socially engineered: what nobody may do on request, who verifies whom, and on which channel

Graduate · enrolled learners

This lesson opens with The Twitter account compromise, 15 July 2020.

What happened
Between about 20:00 and 22:00 UTC on 15 July 2020, 130 high-profile Twitter accounts, among them those of Barack Obama, Joe Biden, Bill Gates, Elon Musk and Apple, posted a message asking followers to send bitcoin to an address with the promise it would be doubled and returned. The attackers had gained access to Twitter's internal administrative tools by social engineering a small number of Twitter employees by phone, and used the tools to reset or take over the accounts and post directly. The scam address received over 320 transfers worth more than $110,000 before the posts were removed and Twitter temporarily blocked all verified accounts from posting. Within weeks three people were charged: Graham Ivan Clark, 17, of Florida, described by the state attorney as the mastermind and charged as an adult on 30 felony counts; Mason Sheppard, 19, of the United Kingdom; and Nima Fazeli, 22, of Florida.
The decision point
The most defended accounts on the platform were posted from without a single password being broken, because the attackers did not attack the accounts. They called the people who could reset them. A platform's employees, and a community's moderators, are the one path that every control on an account is built to trust, and a phone call that sounds like a colleague from the help desk turns that trust into access. The response is not to distrust moderators; it is to write down what no moderator may do on request, from anyone, on any channel, so that the request itself is the signal, and to give every moderator a way to verify a colleague that the attacker does not have.
Recorded loss
$118,000

What you will be able to answer

  • What happened on 15 July 2020?
  • Why are administrators the target?
  • What is on the list nobody may do on request?
  • How do moderators verify each other?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Terms used here

Sources and review

Confidence high·Volatility low·Reviewed 2026-09-14·Owner unassigned

Contested

Reported totals for the scam address range from about $110,000 to about $120,000 depending on the window and price used; the loss_usd figure uses a mid figure and the lesson's arithmetic uses the more conservative one reported at the time.

The precise mechanics of the employee social engineering, including whether credentials or a tool session were obtained, were described by Twitter in general terms. The lesson relies on the company's statement that access to internal tools was obtained through employees by phone.