logo

Security firm Mandiant says it didn’t have 2FA enabled on its hacked Twitter account

ID: 7b1829c5-b8aa-5aef-a971-d0c496f2d52a

STIX ID: report--7b1829c5-b8aa-5aef-a971-d0c496f2d52a

Feed Name: Graham Cluley

Threat Score
45/100

Date Published: 2024-01-11

Date Updated: 2026-04-22

Author: Graham Cluley

...
...

Mandiant’s official Twitter account was hijacked and used to promote a cryptocurrency scam; the company says the takeover was likely a brute-force password attack and that insufficient 2FA (following platform policy changes and team account transitions) left the account vulnerable. Mandiant has published a blog linking the incident to CLINKSLINK wallet-draining malware and says it has updated processes to prevent recurrence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.