State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack)
Key Facts
- Legal Status: SENTENCED in Hillsborough County 13th Judicial Circuit Court.
- Primary Target Sector: Social Media, Public Institutions, Financial Services.
- Documented Financial Loss: $117,000.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Targeted phone spearphishing and employee social engineering scheme compromising Twitter customer support credentials to access internal administrative account management utilities.
Operational & Financial Fallout
Hijacked 130 high-profile verified accounts (including Joe Biden, Barack Obama, Bill Gates, Elon Musk, Kanye West, and Apple), generating $117,000 in fraudulent Bitcoin payments in three hours and creating unprecedented international security panic.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Targeted phone spearphishing and employee social engineering scheme compromising Twitter customer support credentials to access internal administrative account management utilities.
Adversary Kill Chain Flow
3 Documented PhasesClark contacted Twitter customer support staff via telephone claiming to be from the corporate IT support team, directing them to enter their credentials on a spoofed VPN portal.
Using legitimate internal administrative utilities, Clark changed the registered email addresses on 130 target accounts, bypassed 2FA, and reset account passwords instantly.
Attackers posted identical messages promising to double any Bitcoin sent to a specific wallet address, collecting over 12.8 Bitcoin before Twitter locked down verified account posting privileges.
Hijacked 130 high-profile verified accounts (including Joe Biden, Barack Obama, Bill Gates, Elon Musk, Kanye West, and Apple), generating $117,000 in fraudulent Bitcoin payments in three hours and creating unprecedented international security panic.
Procedural & Incident Timeline
Attackers hijack 130 verified Twitter accounts and post Bitcoin doubling scam addresses, earning 12.8 BTC.
FBI, Secret Service, and Florida Department of Law Enforcement arrest 17-year-old Graham Ivan Clark in Tampa.
Clark pleads guilty as a youthful offender and is sentenced to three years in juvenile prison followed by three years probation.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1566.004 | "Clark called Twitter employees on their cellular phones claiming to be from the internal IT department, directing them to enter VPN credentials on a convincing phishing website." | Criminal Information ¶ 4, Page 2 | reviewed | |
| T1078 | Valid Accounts Defense Evasion | "Using stolen employee credentials, Clark logged into Twitter internal customer service management portal ('God Mode'), which allowed direct account recovery email changes and instant password overrides." | Twitter Technical Post-Mortem Investigation | reviewed |