New York finance watchdog says Twitter hack proves social media should be regulated

The New York State Department of Financial Services says social media firms have too much responsibility with little government oversight

Large social media platforms like Twitter should be overseen by a dedicated regulator, according to a new report by a top US financial watchdog.

The report from the New York State Department of Financial Services (DFS) comes exactly three months after a cyber attack against Twitter which saw high-profile celebrity accounts being hacked in order to promote a cryptocurrency scam, leading to the theft of more than $118,000 worth of Bitcoin.

The attack saw hackers obtain log-in credentials to the accounts of Jeff Bezos, Bill Gates and Elon Musk, and others by pretending to work in Twitter’s information technology department. The attackers, led by a 17-year-old resident of Tampa, Florida, duped Twitter staff into sharing the confidential credentials by claiming to be responding to problems with the company’s VPN.

The DFS report found that “the extraordinary access the hackers obtained with this simple technique underscores Twitter’s cybersecurity vulnerability and the potential for devastating consequences”.

In a statement accompanying the report, the watchdog’s financial services superintendent Linda Lacewell said that “social-media platforms have quickly become the leading source of news and information, yet no regulator has adequate oversight of their cybersecurity”.

“The fact that Twitter was vulnerable to an unsophisticated attack shows that self-regulation is not the answer,” she added.

New York governor Andrew Cuomo, who had ordered the probe into the attack, said the report demonstrated a “regulatory gap that must be filled” in order to safeguard “financial and political systems from cyber-attacks and misinformation campaigns”.

“Americans increasingly use and rely on these social media platforms, which means there is no room for weak leadership, systemic errors or flawed cybersecurity when it comes to protecting users and content,” he added. "New York will not hesitate to take the lead with responsible measures that protect our citizens, our systems and our democracy."

Related Resource

2020 cyber security outlook report

Behaviours in the battle between modern attacker and defender

Download now

Twitter said that it had cooperated with the DFS investigation and, since the attack, has implemented additional security training for employees.

“Protecting people’s privacy and security is a top priority for Twitter, and it is not a responsibility we take lightly,” said a spokesperson for the company.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

SonicWall hacked via zero-day flaw in remote access tools
Security

SonicWall hacked via zero-day flaw in remote access tools

25 Jan 2021
Global ransom DDoS extortionists are retargeting companies
distributed denial of service (DDOS)

Global ransom DDoS extortionists are retargeting companies

22 Jan 2021
Best ransomware removal tools
ransomware

Best ransomware removal tools

22 Jan 2021
Hackers publish over 4,000 files stolen from SEPA in ransomware attack
Security

Hackers publish over 4,000 files stolen from SEPA in ransomware attack

22 Jan 2021

Most Popular

How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
WhatsApp could face €50 million GDPR fine
General Data Protection Regulation (GDPR)

WhatsApp could face €50 million GDPR fine

25 Jan 2021
Trump pardons convicted ex-Google engineer Levandowski
intellectual property

Trump pardons convicted ex-Google engineer Levandowski

20 Jan 2021