There has been a surge in listings offering verified Twitter (now X) accounts for sale on dark web marketplaces and surface web platforms, according to cybersecurity firm CloudSEK.
While cybercriminals appear to be focusing on verified Twitter Gold accounts (belonging to companies), verified Twitter accounts owned by individuals (blue tick) and government organizations (grey tick) are also on sale.
Cybercriminals use stolen Twitter Gold accounts to conduct phishing attacks and other scams. Considering X’s popularity and reach, access to verified accounts can be valuable to carry out a variety of scams.
In recent years, cybercriminals have hijacked social media accounts of reputable individuals and organizations to push cryptocurrency and NFT scams. In its report on Wednesday, CloudSEK cited an incident in September 2023 where hackers breached the Twitter account of Ethereum co-founder Vitalik Buterin and swiped up to $691,000 from his followers through an NFT scam.
Even Google-owned cybersecurity firm Mandiant recently fell victim to account hijacking. The incident occurred on January 3, with the attacker changing the account name and handle to impersonate Phantom, a popular crypto wallet. Mandiant regained control of its account a few hours later.
“A hacked or compromised Twitter account can be exploited to mass spread phishing campaigns. This, in turn, damages the reputation and brand of the company whose account was compromised,” CloudSEK said.
Attackers are Targeting Dormant High Profile Accounts
CloudSEK said the X accounts on sale are either created by cybercriminals or hijacked via brute force or malware attacks. Stolen verified accounts have a higher value since they generally have more followers. Accounts belonging to corporations or influencers are the most sought-after.
CloudSEK’s investigation reveals that hackers usually target dormant Twitter accounts. Once stolen, they subscribe to a 30-day Twitter Gold membership and put the account up for sale on dark web marketplaces and forums on surface web platforms like Facebook and Telegram.
“The service package offered by the threat actors ensures that the buyer has no hassles with the account for 30 days (which is also the standard duration of Twitter gold subscriptions). And in the meantime, the scam campaign has achieved its goal through that account,” CloudSEK said.
The price of a stolen Twitter account varies based on the type of subscription and the number of followers. The average cost of a Twitter Blue account is $35, while an old Twitter Gold account can cost $2,000. The sellers also offer associated services, such as boosting followers by 30,000 to 50,000 for $135.
Interestingly, some of these illicit transactions involve a middleman who ensures that the sellers and buyers act in good faith. The middleman checks if the accounts are genuine and inspects the funds the buyer transfers.
How to Protect Your Twitter Account
According to CloudSEK, malicious actors rely on two methods to breach Twitter accounts: brute force attacks or deploying info-stealing malware to harvest passwords.
The most basic ways to protect your Twitter account from brute force attacks include using strong passwords and enabling two-factor authentication on your devices.
We also strongly recommend using a password manager, a virtual private network (VPN), and anti-virus software. A strong anti-virus like Norton 360 protects you from malicious links and files.
Awareness and education can also go a long way to help you avoid common tricks and scams that could compromise your safety online. Read our guide to staying safe online for some valuable cybersecurity tips.
