NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / World

What the Twitter hack revealed: A US election system teeming with risks

By David E. Sanger, Nicole Perlroth and Nick Corasaniti
New York Times·
17 Jul, 2020 02:03 AM9 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

The FBI is investigating how the hackers got inside Twitter's systems. Photo / Jason Henry, The New York Times

The FBI is investigating how the hackers got inside Twitter's systems. Photo / Jason Henry, The New York Times

The breach that targeted Joe Biden, Barack Obama and others served as a warning: Had it happened on November 3, hoping to upend the election, the political fallout could have been quite different.

Over the past year, government officials have raced to help states replace voting machines that leave no paper trail, and to harden vulnerable online voter registration systems that many fear Russia, or others, could hijack to trigger chaos on Election Day.

But this week, the country got a startling vision of other perils in political disinformation — and how many other ways there may be to manipulate turnout, if not votes.

The hacker or hackers who bored into the command centre of Twitter on Wednesday (Thursday NZ time) — seizing control of Joe Biden's and Barack Obama's blue-checked accounts, among many others — served as a warning that some of the most critical infrastructure that could influence the election is not in the hands of government experts, and is far less protected than anyone assumed even a day ago.

The hackers probably did the nation a favor. With a crude scheme to deceive users into thinking that Biden and Obama were asking them for donations in Bitcoin — which sent more than US$120,000 ($182,000) flowing into their cryptocurrency wallets — they revealed how simple it may be to imitate the powerful and the trusted.

Advertisement
Advertise with NZME.

Had saboteurs infiltrated Twitter on November 3 instead of in the middle of July, with the goal of upending the election, the political fallout could have been quite different. False warnings of a coronavirus outbreak in key precincts in Wisconsin or Pennsylvania could have untold effect on a close vote in a battleground state. Deceptive tweets from political party accounts saying polling places were closed could sow confusion.

Or imagine a fake declaration, under Biden's account, that he was dropping out of the race — a nightmare scenario for Democrats that some federal officials said they were talking about hypothetically among themselves Wednesday night as the scope of Twitter's failure became clear.

Similar war gaming about social media and election interference has played out in classified simulations conducted by the Department of Homeland Security, which is responsible for securing the 2020 election, and at Fort Meade, Maryland, home of the National Security Agency and US Cyber Command. The results have never fully been made public.

Advertisement
Advertise with NZME.

But the nation is now getting a very public look at the effect of disinformation when trusted accounts of politicians and prominent Americans are hacked — with voters confused and more wary than ever of who is telling the truth, blue check or no blue check. The disruption revealed that the social media platform favoured by the president — one that the federal courts concluded a year ago is a conduit for official messages about national policy — was as vulnerable, in its own way, as the aging registration databases that Russian intelligence invaded four years ago in Arizona, Illinois and other states.

Investigators are still trying to determine exactly how the hackers got inside Twitter's systems and took such command of the platform that, when Twitter employees took the Bitcoin-seeking messages down, the disinformation popped right back up. Many of the details remain unclear: Investigators are still trying to determine if the hackers tricked a Twitter employee into handing over login information. Twitter suggested Wednesday that the hackers had used "social engineering," a strategy to gain passwords or other personal information by posing as a trusted person like a company representative.

Discover more

Business

Twitter locks down all verified accounts

15 Jul 10:09 PM
Business

Hackers 'paid' Twitter employee to take over high profile accounts

16 Jul 07:18 PM
Business

Twitter struggles to unpack a hack within its walls

17 Jul 12:12 AM
World

White House criticised for saying science 'should not stand in the way' of schools reopening

17 Jul 02:53 AM

But another line of inquiry includes whether a Twitter employee was bribed for his or her credentials, something one person who claimed responsibility for the hacking told the technology site Motherboard.

In the end, it may matter less how they did it than that they succeeded. As Christopher Krebs, who leads the Cybersecurity and Infrastructure Agency at the Department of Homeland Security, has often noted, influencing an election requires either hacking into voter systems or hacking into voters' brains. The Twitter breach demonstrated yet another way to accomplish the latter, what Krebs called Thursday "the more likely, less costly way" to mount an attack.

Until Wednesday's attack, most of the officials and analysts at the array of federal agencies confronting election threats were focused heavily on voting systems — because that is the area over which governments have most control. Their particular worry was a convergence of cybercriminals and national intelligence agencies, particularly in Russia, deploying ransomware against underprotected American cities and towns.

A leaked FBI warning from May 1 said ransomware hackers could seek to lock up registration databases, a move that would disrupt both in-person voting and the mailing and processing of mail-in ballots. The FBI warning suggested that ransomware attacks "will likely threaten the availability of data on interconnected election servers, even if that is not the actors' intention."

People voted at a library in Dallas this week. The hacking of Twitter on Wednesday revealed another potential avenue for election interference. Photo / Nitashia Johnson, The New York Times
People voted at a library in Dallas this week. The hacking of Twitter on Wednesday revealed another potential avenue for election interference. Photo / Nitashia Johnson, The New York Times

The bureau had reason to worry: Atlanta, Baltimore and towns across Florida and Texas have been victims of attacks that locked up their data, making it impossible to pay taxes, get potholes fixed or obtain a building permit. The advisory noted that cybercriminals broke into the American companies that provide internet services to Louisiana election officials late last year, then carefully timed their ransomware attack to a week before an election.

It was a wake-up call, FBI analysts said, to what American states and counties might expect in 2020.

Advertisement
Advertise with NZME.

But the Twitter hacking suggested yet another vector for attack. And it was a reminder of three particular challenges facing those trying to secure the election. The first is assessing possible vulnerabilities so the country is not playing catch-up once again, long after Election Day, to outside interference with the election system or on social media. (The extent of Russia's manipulation of Facebook posts in 2016, for example, became clear only after President Donald Trump had been elected.)

The second is how well the country can lock down these systems in the 100-plus days left before the election, beyond the obvious "critical infrastructure" that will enable the November 3 vote. And the third is whether it is possible to build some national resilience to respond quickly, as Twitter tried, if something goes wrong.

Since 2016, thousands of pages of federal investigative reports have been published on what went wrong in the presidential election that year, and a congressional Cyberspace Solarium Commission has produced long lists of recommendations of how private enterprise and the government can work together.

But then there are days like Wednesday, when it seems as if all the studies were insufficient.

"We have seen disconcerting incidents of account takeovers before," said John Hultquist, the senior director of intelligence analysis at FireEye, one of the leading cybersecurity firms, "but we are very concerned about the possibility of real foreign actors hijacking legitimate sources of information — key media accounts for instance — and using that to push out disinformation" close to Election Day.

"By the time we unwind everything to figure out what happened, it could be too late," he added. "That's a very real scenario."

Or, as Laura Rosenberger, a former State Department official who now directs the Alliance for Securing Democracy project at the German Marshall Fund, noted, "What hasn't changed is our failure to think ahead. Our adversaries have an ability to turn this infrastructure, which we have created, against us, and we need to be better at anticipating the threat vectors."

Similar thoughts haunt state election officials on both sides of the aisle who say they are alarmed about what could happen if the mega-microphones of accounts belonging to the likes of Biden or Obama broadcast a bit of electoral disinformation.

Alex Padilla, the secretary of state in California, home to Twitter headquarters, said that while state officials had run simulations of a social media disinformation campaign disrupting an election day, they hadn't imagined a situation in which Twitter itself was hacked. Still, he said, threats posed by disinformation motivated him to set up VoteSure, a statewide voting information effort sparked by the special counsel's investigation of Russian interference in the 2016 election.

"I wouldn't say it was a new concern, but I would say it's a big reminder given what we've all been through over the last four years," Padilla said.

In Ohio, Frank LaRose, the secretary of state, has been conducting seminars to inform local officials about disinformation tactics and how to respond, and directing much of Ohio's federal election funds to shoring up election security. But the attack on Twitter opened a new front, he said.

"From my time in the Army, I learned that the enemy is always going to be innovating to try to find our vulnerabilities," LaRose said in a statement. "We're doing everything we can to stay ahead of the curve, including going straight into targeted communities and arming them with the tools they need to fight back against disinformation."

Of course, no one should be shocked at high-profile account takeovers: The account of Jack Dorsey, Twitter's chief executive, was compromised last year. Last year, two Twitter employees were accused of abusing their access to aid Saudi Arabia's efforts to spy on dissidents abroad.

And as far back as 2013, the Syrian Electronic Army hacked The Associated Press's Twitter account, issuing false warnings that an explosion at the White House had injured Obama. By the time the tweet could be corrected, and the hackers exposed, the stock market had plunged.

Seven years later, fears are heightened by the uncertainty over how to deal with life in a so-called dirty network, where data and information are coursing through Americans' phones on apps of questionable security — Twitter is now in that category — or under foreign control.

That is why companies ranging from PayPal and Wells Fargo, and political organizations like the Democratic National Committee, have told employees to delete the Chinese social media app TikTok from their corporate devices. On Wednesday, as the Twitter drama was unfolding, Trump's chief of staff, Mark Meadows, said the government was considering banning TikTok entirely.

"There are a number of administration officials who are looking at the national security risk as it relates to TikTok, WeChat and other apps that have the potential for national security exposure," Meadows said on Air Force One, "specifically as it relates to the gathering of information on American citizens by a foreign adversary."

But Twitter is an American company — no one is going to ban it — and it's the way that Meadows' boss communicates with his constituents and, often, with his own government. The question is whether its security flaws can be fixed in the next 16 weeks.


Written by: David E. Sanger, Nicole Perlroth and Nick Corasaniti
Photographs by: Nitashia Johnson and Jason Henry
© 2020 THE NEW YORK TIMES

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from World

WorldUpdated

'No sense': Defence challenges motive in mushroom poisoning case

17 Jun 07:34 AM
World

'Everyone evacuate': Trump's warning amid G7 Middle East talks

17 Jun 07:15 AM
World

Body in bushland confirmed as missing teen Pheobe Bishop

17 Jun 04:47 AM

Jono and Ben brew up a tea-fuelled adventure in Sri Lanka

sponsored
Advertisement
Advertise with NZME.

Latest from World

'No sense': Defence challenges motive in mushroom poisoning case

'No sense': Defence challenges motive in mushroom poisoning case

17 Jun 07:34 AM

Prosecutors allege she poisoned her in-laws with death cap mushrooms.

'Everyone evacuate': Trump's warning amid G7 Middle East talks

'Everyone evacuate': Trump's warning amid G7 Middle East talks

17 Jun 07:15 AM
Body in bushland confirmed as missing teen Pheobe Bishop

Body in bushland confirmed as missing teen Pheobe Bishop

17 Jun 04:47 AM
Why UK abortion law overhaul is crucial for women's rights

Why UK abortion law overhaul is crucial for women's rights

17 Jun 04:39 AM
Help for those helping hardest-hit
sponsored

Help for those helping hardest-hit

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP