美国时间15日,推特发生了大规模盗号现象,而且一个个还都是重量级帐号,包括美国民主党总统候选人乔拜登、微软创始人比尔盖茨、特斯拉公司CEO埃隆马斯克以及苹果公司等帐号,纷纷中招。
Twitter accounts belonging to Joe Biden, Bill Gates, Elon Musk and Apple, among other prominent handles, were compromised on Wednesday.
这些帐号都发布了关于虚拟货币骗局的推文。
The attackers posted tweets that appeared to promote a cryptocurrency scam.
BBC:重量级美国推特帐号被比特币骗局劫持
比如乔拜登的帐号就有这样的内容:“我要回馈社区。所有给以下账号发送比特币的人都会得到双倍回报!送我1000美元,返回2000美元。仅30分钟内有效。”
还有比尔盖茨的帐号:“每个人都要我做出回馈,现在是时候了。接下来的30分钟内,给我比特币账号送钱的人,我会双倍奉还。你给我1000美元,我给你2000美元。仅30分钟内有效!好好享受吧!”
马斯克:“因为疫情影响,我感觉要慷慨一点。一小时内给我比特币账号付钱的人,我将双倍返还。祝你好运,大家都好好的!”
苹果公司:“我们要回馈社会了。我们支持比特币,并且相信你也应该支持。所有发送到这个账号的比特币会得到双倍返还。仅30分钟内有效。”
被黑的认证账户远不止这些,还有奥巴马、侃爷及妻子金卡戴珊、巴菲特、贝索斯等等,并且都发送了类似的比特币筹款推文。
The accounts, along with those of former U.S President Barack Obama, Kanye West, Kim Kardashian West, Warren Buffett and Jeff Bezos, posted similar tweets soliciting donations via Bitcoin to their verified profiles on Wednesday.
有些名人的推特中,诈骗信息并不止一条。比如前纽约市长布隆伯格的推特中,还有“又送出了40000美元的字样”。
外媒:无所顾忌的攻击
这样针对性十足的操作,也令外媒十分震惊,《纽约时报》称之为无所顾忌的攻击。
《纽约时报》网站:一场以比特币骗局方式,针对推特VIP用户无所顾忌的线上攻击
“炫耀武力一般,黑客获取了推特最重要的账户,包括政客、娱乐圈和科技名人。”
《纽约时报》的这篇报道指出,推特当时很迅速地删掉了一些推文,然而相似的推文在相同的账户上死灰复燃,让人感觉推特对于重新拿回控制权无能为力。
Twitter quickly removed many of the messages, but in some cases similar tweets were sent again from the same accounts, suggesting that Twitter was powerless to regain control.
而黑客们没有将重要机构和设施设为目标——仅仅是要比特币。但是这一波攻击足以让安全专家担忧,因为这显示出黑客们可能会造成更严重的“浩劫”。
The hackers did not use their access to take aim at any important institutions or infrastructure — instead just asking for Bitcoin. But the attack was concerning to security experts because it suggested that the hackers could have easily caused much more havoc.
截至美国东部时间15日晚,据相关比特币交易记录网站数据显示,这些诈骗推文中的比特币钱包共收到超过300笔交易,价值超过10万美元。
By Wednesday evening, the Bitcoin wallets promoted in the tweets had received over 300 transactions and Bitcoin worth over $100,000, according to websites that track Bitcoin’s public ledger of transactions.
该报道中还援引了相关网站做出的时间线统计,在三个小时中,骗局中的比特币钱包共收到11.8万美元。
图源:《纽约时报》网站
网络安全公司CrowdStrike的联合创始人Dmitri Alperovitch在接受路透社采访时表示,“这是迄今为止针对主流社交媒体平台最严重的黑客攻击事件。”
Dmitri Alperovitch, who co-founded cyber-security company CrowdStrike, told Reuters news agency: "This appears to be the worst hack of a major social media platform yet."
推特CEO:艰难的一天
面对如此情形,推特CEO杰克多西周三发推直言,“这是艰难的一天。”
In a tweet on Wednesday, CEO Jack Dorsey said it was a "tough day for us at Twitter."
“我们对此感觉很糟糕,我们正在诊断问题,当我们对此事有一个更完整了解的时候,我们会把一切分享给大家。”
"We all feel terrible this happened," Dorsey said. "We're diagnosing and will share everything we can when we have a more complete understanding of exactly what happened."
推特技术支持团队于15日晚发布声明表示:“监测到协作的带有‘社交工程’色彩的网络攻击, 此次攻击的发起方通过协同配合,成功对准了若干名推特内部员工,而这些员工具备进入内网系统的权限及网络工具”。推特在注意到这一情况后,立即锁定了受影响的帐号,移除了相关内容。“我们锁定了暴露给黑客的账户,只有当确认安全后,我们才会让账户原主人登录。”
"We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools," Twitter's support team said late Wednesday. "Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers," Twitter said. "We have locked accounts that were compromised and will restore access to the original account owner only when we are certain we can do so securely."
而在推特解决事件期间,有些用户不能正常发推或者进行重置密码操作。
据《纽约时报》报道,目前尚未得知攻击的始作俑者。不过,一位美国高级情报官员注意到,众多名人帐号纷纷中招,但是在推特上“备受关注且有权有势的”一人却没有受到波及:那就是美国总统特朗普。因为特朗普帐号采用了特殊的加密解密手段。
There was little immediate evidence for who conducted the attack. One senior American intelligence official noted that the breach did not affect the account of one of the most watched and powerful users of Twitter: U.S President Trump. Trump’s account is under a special kind of lock-and-key, the official noted.
此外,美国联邦调查局已经开始调查这一事件。
美国参议院商务委员会则要求推特在23日前就此事件做出相关说明。
The US Senate Commerce committee has demanded Twitter brief it about Wednesday's incident by 23 July.
综合来源:新华网,观察者网,CNN,BBC,WSJ,NYTimes