CASE DOSSIER sentenced

State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack)

Docket: 20-CF-008922 Court: Hillsborough County 13th Judicial Circuit Court Opened: 2020-07-31 Sector: Social Media, Public Institutions, Financial Services

Key Facts

Status
SENTENCED
Legal disposition
Loss Amount
$117,000
Extorted $117,000 in direct Bitcoin transfers in under three hours, causing immense international security concerns and stock volatility.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SENTENCED in Hillsborough County 13th Judicial Circuit Court.
  • Primary Target Sector: Social Media, Public Institutions, Financial Services.
  • Documented Financial Loss: $117,000.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

17-year-old hacker orchestrated a spearphishing and social engineering scheme targeting Twitter employees, gaining access to internal administrative customer service tools and hijacking 130 high-profile verified accounts (including Joe Biden, Barack Obama, Elon Musk, and Apple) to promote a fraudulent Bitcoin giveaway.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Targeted phone spearphishing and employee social engineering scheme compromising Twitter customer support credentials to access internal administrative account management utilities.

Operational & Financial Fallout

Hijacked 130 high-profile verified accounts (including Joe Biden, Barack Obama, Bill Gates, Elon Musk, Kanye West, and Apple), generating $117,000 in fraudulent Bitcoin payments in three hours and creating unprecedented international security panic.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SENTENCED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Targeted phone spearphishing and employee social engineering scheme compromising Twitter customer support credentials to access internal administrative account management utilities.

Adversary Kill Chain Flow

3 Documented Phases
1
Phone Spearphishing Employee Helpdesk Impersonation
MITRE ATT&CK T1566.004 →

Clark contacted Twitter customer support staff via telephone claiming to be from the corporate IT support team, directing them to enter their credentials on a spoofed VPN portal.

Artifacts & Tooling: Spoofed VPN portal Phone social engineering
2
Tooling Abuse Twitter Internal Administrative Tool Hijack
MITRE ATT&CK T1078 →

Using legitimate internal administrative utilities, Clark changed the registered email addresses on 130 target accounts, bypassed 2FA, and reset account passwords instantly.

Artifacts & Tooling: Twitter internal support dashboard ('God Mode') Email override API
3
Cryptocurrency Extortion Automated Social Media Bitcoin Scam
MITRE ATT&CK T1486 →

Attackers posted identical messages promising to double any Bitcoin sent to a specific wallet address, collecting over 12.8 Bitcoin before Twitter locked down verified account posting privileges.

Artifacts & Tooling: Bitcoin vanity address Automated tweet posting
Real-World Blast Radius & Operational Fallout

Hijacked 130 high-profile verified accounts (including Joe Biden, Barack Obama, Bill Gates, Elon Musk, Kanye West, and Apple), generating $117,000 in fraudulent Bitcoin payments in three hours and creating unprecedented international security panic.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Require multiple independent administrative approvals for sensitive actions on high-profile accounts.
✓ Enforce FIDO2 hardware security keys for internal tool authentication, blocking credential harvesting over the phone.
✓ Implement automated anomaly detection on bulk password resets and email modifications.
✓ Adopt principle of least privilege, restricting customer support representatives from full account takeover capabilities.

Procedural & Incident Timeline

2020-07-15 incident

Attackers hijack 130 verified Twitter accounts and post Bitcoin doubling scam addresses, earning 12.8 BTC.

2020-07-31 arrest

FBI, Secret Service, and Florida Department of Law Enforcement arrest 17-year-old Graham Ivan Clark in Tampa.

2021-03-16 sentencing

Clark pleads guilty as a youthful offender and is sentenced to three years in juvenile prison followed by three years probation.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1566.004
"Clark called Twitter employees on their cellular phones claiming to be from the internal IT department, directing them to enter VPN credentials on a convincing phishing website." Criminal Information ¶ 4, Page 2 reviewed
T1078 Valid Accounts
Defense Evasion
"Using stolen employee credentials, Clark logged into Twitter internal customer service management portal ('God Mode'), which allowed direct account recovery email changes and instant password overrides." Twitter Technical Post-Mortem Investigation reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack), No. 20-CF-008922 (Hillsborough County 13th Judicial Circuit Court 2020), https://cybercaselibrary.com/cases/us-v-clark-twitter-bitcoin/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-clark-twitter-bitcoin" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>