09 Mar 2009
Twitter users once again experienced the unpleasant side of Web 2.0 over the weekend as the popular microblogging site was hacked and messages were sent out over users' feeds encouraging visitors to follow a potentially malicious link.
Over 700 accounts were compromised, allowing the hacker to post the following message and related link in their feeds: "hey! 23/Female. Come chat with me on my webcam thingy here".
According to Rik Ferguson, solutions architect at security vendor Trend Micro, the link takes users to a porn webcam portal which "looks to have been designed with credit card harvesting in mind".
In a posting on the Twitter blog, the firm said it had reset the passwords of any compromised accounts and "removed the spammy updates". It advised users to always choose strong passwords and to avoid sharing passwords with untrustworthy sites.
It's still unclear how the user accounts were hacked in the first place, although some commentators have pointed to a similar attack about a month ago.
"You don't have to be Albert Einstein to put two and two together, and deduce that these attacks must be related," wrote Sophos senior technology consultant Graham Cluley in his blog.
"We're seeing more and more attacks from spammers, phishers, malware authors, scammers and identity thieves against the users of social networks like Twitter and Facebook. These aren't just proof-of-concept attacks in controlled conditions - they're full-blooded assaults seen in the wild every day, making money out of real people."
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
EU data protection overhaul contains "bureaucratic tick box-proposals", says information commissioner Christopher Graham in exclusive interview with V3
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
My client is one of the most successful and highly regarded...
Java/J2EE, Agile, Scrum, Test driven development, Pair...
C# / ASP.NET Software Developer - Online Gambling - London...
Developer, Gaming / Finance, 35-50k My client are...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
<p>I'm wondering if my account has been hacked? I cannot access and have NOT changed a thing. I CANNOT create a support ticket for that very reason. Twitter should have a support e-mail address for those who cannot log-in to create a trouble ticket! Can someone please see if my account has been HACKED or what the problem is. I still send a twitter every so often<br /> and my last up date via 40404 was followed by a e-mail notification that someone from Twitter.com/thepodcast was following my twitters. Please help me resolve. Reeni </p>
Posted by: Anonymous 28 Mar 2009
<p>Hi. Can someone tell me a contact e-mail address were I can send a message to. I think that my Twitter-Account was hacked, too. And I could not change my passwort or anything else. So I need help. I wrote to a few twitter-email-adresses but I got no reply. </p>
Posted by: Sandra 24 Mar 2009