Skip to content
Weekly Geek
  • Comics
  • Film
  • SciFi
  • Sports
  • Tech
  • TV
  • Video Games
  • Wrestling

Mandiant, the security firm Google bought for $5.4 billion, gets its X account hacked

By TheGeek | January 3, 2024
0 Comment
Mandiant, the security firm Google bought for $5.4 billion, gets its X account hacked

reader comments

36

Google-owned security firm Mandiant spent several hours trying to regain control of its account on X (formerly known as Twitter) on Wednesday after an unknown scammer hijacked it and used it to spread a link that attempted to steal cryptocurrency from people who clicked on it.

“We are aware of the incident impacting the Mandiant X account and are working to resolve the issue,” company officials wrote in a statement. “We’ve since regained control over the account and are currently working on restoring it.” The statement didn’t answer questions asking if the company had determined how the account was compromised.

The hacked Mandiant account was initially used to masquerade as one belonging to Phantom, a company that offers a wallet for storing cryptocurrency. Posts on X encouraged people to visit a malicious website to see if their wallet was one of 250,000 that were eligible for an award of tokens. Over several hours, X employees played tug-of-war with the unknown scammer, with scam posts being removed only to reappear, according to people who followed the events.

  • Mandiant profile page claiming to be affiliated with “friendly crypto wallet” Phantom.
  • One of the scam posts spread by the hijacked Mandiant account.

Eventually, the scammer changed the @mandiant username and reappeared under a new username. After using the account to promote a fake website impersonating Phantom and promising free tokens, it posted the cryptic message: “check bookmarks when you get account back.” It also chided Mandiant to “change password please.”

Advertisement
  • Post saying “change password please”
  • Post saying to check bookmarks

At the time this post went live on Ars, the Mandiant profile displayed the message “This account doesn’t exist.”

Mandiant profile declaring "this account doesn't exist."
Enlarge / Mandiant profile declaring “this account doesn’t exist.”

Mandiant is one of the leading security companies and best known for helping clients investigate and recover from major network compromises. That vantage point gives it major insights into threat actors, many of them backed by nation-states, and the often previously unknown tactics, techniques, and procedures they use to compromise the security of some of the world’s most powerful and well-resourced organizations. Google purchased Mandiant in 2022 for $5.4 billion, which, at the time, was its second-biggest acquisition ever.

Many questions remain about Mandiant’s measures to secure its X account. Among them: Was it protected by a strong password and any form of two-factor authentication? Last month, someone claimed to have discovered the social media site was vulnerable to a “reflected XSS,” a type of vulnerability that can sometimes be used to compromise the security of accounts when a legitimate user currently logged in clicks on a malicious link in a different browser tab. The user said they reported the vulnerability through legitimate channels but that the submission didn’t qualify under the X bug bounty program.

“Clicking a crafted link or going to some crafted web pages would allow attackers to take over your account (posting, liking, updating your profile, deleting your account, etc.),” Chaofan Shou, a University of California at Berkeley Ph.D. candidate, wrote last month.

December 12 post by UC Berkeley Ph.D. candidate Chaofan Shou.
Enlarge / December 12 post by UC Berkeley Ph.D. candidate Chaofan Shou.

Attempts to reach Phantom for comment were unsuccessful.

Source

Category: Tech Tags: account hijack, Biz & IT, google, Mandiant, security, Twitter
Post navigation
← Best NBA Prop Bets Tonight (Jan. 3): Live updates on LeBron James points, Scottie Barnes rebounds, more NFL Pro Bowl rosters 2024: Updated list of selections, alternates, coaches for AFC & NFC teams →

Recent Posts

  • Rockets trade proposal lands All-Star guard after Fred VanVleet injury
  • Insider provides the latest on Artemi Panarin’s Rangers future
  • Experts urge caution about using ChatGPT to pick stocks
  • As many as 2 million Cisco devices affected by actively exploited 0-day
  • ‘SI’ Swim shares a throwback so steamy it adds ‘adult content’ warning

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020

Categories

  • Books
  • Comics
  • Film
  • SciFi
  • Sports
  • Tech
  • TV
  • Uncategorized
  • Video Games
  • Wrestling
custom footer text left
custom footer text right
Iconic One Theme | Powered by Wordpress