Security

Hackers are spreading Islamic State propaganda by hijacking dormant Twitter accounts

Comment

two people silhouetted in front of wall bearing Twitter logo
Image Credits: Bloomberg / Getty Images

Hackers are using a decade-old flaw to target and hijack dormant Twitter accounts to spread terrorist propaganda, TechCrunch has learned.

Many of the affected Twitter accounts appeared to be hijacked in recent days or weeks — some longer — after years of inactivity. A sudden shift in tone or the language used in tweets often gives away the hijack — usually a single tweet in Arabic, sometimes praising Allah or retweeting propaganda from another account.

Twitter has suspended most of the accounts we reviewed, but some remain active.

The recent resurgence in hijacked accounts appears to be hackers exploiting Twitter’s legacy lack of email confirmation. Twitter took steps to prevent the automated creation of new accounts in June by requiring new accounts to be confirmed using an email address or phone number, but many older accounts remain unconfirmed.

But while dormant Twitter accounts are never deleted, the email addresses that were used to create them either never existed in the first place, or expired long ago. As such, many older Twitter accounts can be easily hijacked by creating the email address used to initially register the Twitter account.

“This issue has been around for a while but no one really knew and took advantage of it,” said a hacker and security researcher known as WauchulaGhost, who researches and disrupts the online activities of the so-called Islamic State.

“Now, we have Islamic State supporters that have figured it out,” he said.

He found one since-suspended account following many inactive accounts, which had all been recently hijacked. His hypothesis was that, “once you create the email, password reset on the Twitter account, check the email and click the link,” he said. Many of those dormant accounts he tested hadn’t created the email that the account was registered to. The email addresses are partially masked, but it’s easy to tell how many characters are in a Twitter account’s email address. Often the email accounts were simply their Twitter handle at “@hotmail.com” or “@yahoo.com,” he said.

Some of the accounts had tens of thousands of followers, he said.

He shared several of those dormant Twitter accounts with TechCrunch, nearly all of which had registered email addresses that were identical to their Twitter handle. He was able to register all of those email addresses, which would have allowed him to access those accounts.

Many of the hijacked accounts he found in the past few days — and shared with TechCrunch — were spreading propaganda, but were later suspended from the service. The hackers often didn’t bother to change the bios on the account.

The hijacked accounts we reviewed included Arabic-speaking videos of Islamic State fighters wielding weapons and other curated content. Others simply contained text — also in Arabic — that praised violence and other attacks, or retweeted other accounts.

A propaganda video including Syrian fighters. (Screenshot: TechCrunch)
A communique from Islamic State’s affiliated news outlet Amaq describing an attack by fighters in Yemen in December. (Screenshot: TechCrunch)

One tweet, roughly translated, used an Islamic State hashtag: “…with your cars, let’s go pack, you bomb, go with a bomb, you go in any way.” Another hijacked account called on Muslims to “kill these Christians wherever you find them,” while another account tweeted about turning the Christmas holidays “into grief and horror.” (These statements go against fundamental Islamic teachings, and calls for violence against non-Muslims is expressly forbidden in the Qur’an.)

In English, quote tweeting a since-suspended account inciting violence against “non-believers” citizens in an unnamed country. (Screenshot: TechCrunch)
Another former English-language Twitter account, since hijacked, spreading messages in Arabic about Saudi Arabia’s involvement in Yemen. (Screenshot: TechCrunch)

Twitter said it’s trying to find a solution to a problem that it claims isn’t theirs to fix.

“Reusing email addresses in this manner is not a new issue for Twitter or other online services,” a Twitter spokesperson told TechCrunch. “For our part, our teams are aware and are working to identify solutions that can help keep Twitter accounts safe and secure.”

In other words, it’s the email providers — like Hotmail and Yahoo — that are deactivating accounts and recycling email addresses that are partly the problem — on top of Twitter’s lack of confirming accounts for the first decade of the service’s existence. And Twitter isn’t alone: Facebook also struggled with account hijacks through expired email accounts.

But the researcher said Twitter should shoulder the blame for the account hijacks.

Twitter said it has removed over a million accounts for promoting and sharing content since August 2015 — with more than 205,000 accounts during the first half of 2018 alone. The number of accounts suspended has declined in each reporting period as Twitter claims its technologies are preventing pro-terrorism accounts from spreading content in the first place. Even during the reporting for this story, we’ve even seen account after account get suspended off the site by Twitter. But around one-quarter of accounts that are eventually caught are still able to tweet at least once, it says.

Twitter knows it has a problem. But with other companies as much at fault, neither they — nor the social media giant — appears to have a way to fix it.

Twitter claims more progress on squeezing terrorist content

More TechCrunch

eBay’s newest AI feature allows sellers to replace image backgrounds with AI-generated backdrops. The tool is now available for iOS users in the U.S., U.K., and Germany. It’ll gradually roll…

eBay debuts AI-powered background tool to enhance product images

If you’re anything like me, you’ve tried every to-do list app and productivity system, only to find yourself giving up sooner than later because sooner than later, managing your productivity…

Hoop uses AI to automatically manage your to-do list

Asana is using its work graph to train LLMs with the goal of creating AI assistants that work alongside human employees in company workflows.

Asana introduces ‘AI teammates’ designed to work alongside human employees

Taloflow, an early stage startup changing the way companies evaluate and select software, has raised $1.3M in a seed round.

Taloflow puts AI to work on software vendor selection to reduce cost and save time

The startup is hoping its durable filters can make metals refining and battery recycling more efficient, too.

SiTration uses silicon wafers to reclaim critical minerals from mining waste

Spun out of Bosch, Dive wants to change how manufacturers use computer simulations by both using modern mathematical approaches and cloud computing.

Dive goes cloud-native for its computational fluid dynamics simulation service

After growing 500% year-over-year in the past year, Understory is now launching a product focused on the renewable energy sector.

Insurance provider Understory gets into renewable energy following $15M Series A

Ashkenazi will start her new role at Google’s parent company on July 31, after 23 years at Eli Lilly.

Alphabet’s brings on Eli Lilly’s Anat Ashkenazi as CFO

Tobiko aims to reimagine how teams work with data by offering a dbt-compatible data transformation platform.

With $21.8M in funding, Tobiko aims to build a modern data platform

In 1816, French physician René Laennec invented an instrument that allowed doctors to listen to human hearts and lungs. That device — a stethoscope — eventually evolved from a simple…

Eko Health scores $41M to detect heart and lung disease earlier and more accurately

The number of satellites on low Earth orbit is poised to explode over the coming years as more mega-constellations come online, and it will create new opportunities for bad actors…

DARPA and Slingshot build system to detect ‘wolf in sheep’s clothing’ adversary satellites

SAP sees WalkMe’s focus on automating contextual, in-app support as bringing value to its own enterprise customers.

SAP to acquire digital adoption platform WalkMe for $1.5B

The National Democratic Alliance (NDA) has emerged victorious in India’s 2024 general election, but with a smaller majority compared to 2019. According to post-election analysis by Goldman Sachs, JP Morgan,…

Modi-led coalition’s election win signals policy continuity in India – but also spending cuts

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

17 hours ago
A comprehensive list of 2024 tech layoffs

Featured Article

What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

Apple is hoping to make WWDC 2024 memorable as it finally spells out its generative AI plans.

18 hours ago
What to expect from WWDC 2024: iOS 18, macOS 15 and so much AI

We just announced the breakout session winners last week. Now meet the roundtable sessions that really “rounded” out the competition for this year’s Disrupt 2024 audience choice program. With five…

The votes are in: Meet the Disrupt 2024 audience choice roundtable winners

The malicious attack appears to have involved malware transmitted through TikTok’s DMs.

TikTok acknowledges exploit targeting high-profile accounts

It’s unusual for three major AI providers to all be down at the same time, which could signal a broader infrastructure issues or internet-scale problem.

AI apocalypse? ChatGPT, Claude and Perplexity all went down at the same time

Welcome to TechCrunch Fintech! This week, we’re looking at LoanSnap’s woes, Nubank’s and Monzo’s positive milestones, a plethora of fintech fundraises and more! To get a roundup of TechCrunch’s biggest…

A look at LoanSnap’s troubles and which neobanks are having a moment

Databricks, the analytics and AI giant, has acquired data management company Tabular for an undisclosed sum. (CNBC reports that Databricks paid over $1 billion.) According to Tabular co-founder Ryan Blue,…

Databricks acquires Tabular to build a common data lakehouse standard

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

The next few weeks could be pivotal for Worldcoin, the controversial eyeball-scanning crypto venture co-founded by OpenAI’s Sam Altman, whose operations remain almost entirely shuttered in the European Union following…

Worldcoin faces pivotal EU privacy decision within weeks

OpenAI’s chatbot ChatGPT has been down for several users across the globe for the last few hours.

OpenAI fixes the issue that caused ChatGPT outage for several hours

True Fit, the AI-powered size-and-fit personalization tool, has offered its size recommendation solution to thousands of retailers for nearly 20 years. Now, the company is venturing into the generative AI…

True Fit leverages generative AI to help online shoppers find clothes that fit

Audio streaming service TuneIn is teaming up with Discord to bring free live radio to the platform. This is TuneIn’s first collaboration with a social platform and one that is…

Discord and TuneIn partner to bring live radio to the social platform

The early victors in the AI gold rush are selling the picks and shovels needed to develop and apply artificial intelligence. Just take a look at data-labeling startup Scale AI…

Scale AI founder Alexandr Wang is coming to Disrupt 2024

Try to imagine the number of parts that go into making a rocket engine. Now imagine requesting and comparing quotes for each of those parts, getting approvals to purchase the…

Engineer brothers found Forge to modernize hardware procurement

Raspberry Pi has released a $70 AI extension kit with a neural network inference accelerator that can be used for local inferencing, for the Raspberry Pi 5.

Raspberry Pi partners with Hailo for its AI extension kit

When Stacklet’s founders, Travis Stanfield and Kapil Thangavelu, came out of Capital One in 2020 to launch their startup, most companies weren’t all that concerned with constraining cloud costs. But…

Stacklet sees demand grow as companies take cloud cost control more seriously

Fivetran’s Managed Data Lake Service aims to remove the repetitive work of managing data lakes.

Fivetran launches a managed data lake service