{
  "id": "case-clark-twitter-bitcoin",
  "slug": "us-v-clark-twitter-bitcoin",
  "title": "State of Florida v. Graham Ivan Clark (Twitter VIP Bitcoin Hijack)",
  "summary": "17-year-old hacker orchestrated a spearphishing and social engineering scheme targeting Twitter employees, gaining access to internal administrative customer service tools and hijacking 130 high-profile verified accounts (including Joe Biden, Barack Obama, Elon Musk, and Apple) to promote a fraudulent Bitcoin giveaway.",
  "case_number": "20-CF-008922",
  "court": "Hillsborough County 13th Judicial Circuit Court",
  "district": "Hillsborough County",
  "country": "United States",
  "opened_at": "2020-07-31",
  "status": "sentenced",
  "victim_sector": "Social Media, Public Institutions, Financial Services",
  "victim_country": "United States",
  "loss_amount_usd": 117000,
  "loss_amount_note": "Extorted $117,000 in direct Bitcoin transfers in under three hours, causing immense international security concerns and stock volatility.",
  "first_seen_at": "2020-07-15T15:00:00Z",
  "last_updated_at": "2026-08-14T11:00:00Z",
  "actor_slug": "kirk-clark-twitter-conspiracy",
  "defendant_slugs": [
    "graham-ivan-clark"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1566.004",
      "evidence_excerpt": "Clark called Twitter employees on their cellular phones claiming to be from the internal IT department, directing them to enter VPN credentials on a convincing phishing website.",
      "evidence_locator": "Criminal Information \u00b6 4, Page 2",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Florida State Attorney Information",
      "source_url": "https://www.sao13th.com"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Using stolen employee credentials, Clark logged into Twitter internal customer service management portal ('God Mode'), which allowed direct account recovery email changes and instant password overrides.",
      "evidence_locator": "Twitter Technical Post-Mortem Investigation",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Twitter Official Incident Report",
      "source_url": "https://blog.twitter.com",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2020-07-15",
      "description": "Attackers hijack 130 verified Twitter accounts and post Bitcoin doubling scam addresses, earning 12.8 BTC."
    },
    {
      "event_type": "arrest",
      "event_date": "2020-07-31",
      "description": "FBI, Secret Service, and Florida Department of Law Enforcement arrest 17-year-old Graham Ivan Clark in Tampa."
    },
    {
      "event_type": "sentencing",
      "event_date": "2021-03-16",
      "description": "Clark pleads guilty as a youthful offender and is sentenced to three years in juvenile prison followed by three years probation."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Targeted phone spearphishing and employee social engineering scheme compromising Twitter customer support credentials to access internal administrative account management utilities.",
    "blast_radius": "Hijacked 130 high-profile verified accounts (including Joe Biden, Barack Obama, Bill Gates, Elon Musk, Kanye West, and Apple), generating $117,000 in fraudulent Bitcoin payments in three hours and creating unprecedented international security panic.",
    "kill_chain": [
      {
        "phase": "Phone Spearphishing",
        "title": "Employee Helpdesk Impersonation",
        "description": "Clark contacted Twitter customer support staff via telephone claiming to be from the corporate IT support team, directing them to enter their credentials on a spoofed VPN portal.",
        "technical_artifacts": [
          "Spoofed VPN portal",
          "Phone social engineering"
        ],
        "mitre_technique_id": "T1566.004"
      },
      {
        "phase": "Tooling Abuse",
        "title": "Twitter Internal Administrative Tool Hijack",
        "description": "Using legitimate internal administrative utilities, Clark changed the registered email addresses on 130 target accounts, bypassed 2FA, and reset account passwords instantly.",
        "technical_artifacts": [
          "Twitter internal support dashboard ('God Mode')",
          "Email override API"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Cryptocurrency Extortion",
        "title": "Automated Social Media Bitcoin Scam",
        "description": "Attackers posted identical messages promising to double any Bitcoin sent to a specific wallet address, collecting over 12.8 Bitcoin before Twitter locked down verified account posting privileges.",
        "technical_artifacts": [
          "Bitcoin vanity address",
          "Automated tweet posting"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Require multiple independent administrative approvals for sensitive actions on high-profile accounts.",
      "Enforce FIDO2 hardware security keys for internal tool authentication, blocking credential harvesting over the phone.",
      "Implement automated anomaly detection on bulk password resets and email modifications.",
      "Adopt principle of least privilege, restricting customer support representatives from full account takeover capabilities."
    ]
  }
}