The Twitter and YouTube accounts of the British Army were used to promote NFT and other crypto scams. The YouTube account was used to transmit an older Elon Musk clip that attempts to trick users into visiting cryptocurrency scam sites.
The attackers hijacked the verified Twitter account of the British Army, changed the profile images, and renamed it to ‘pssssd.’
After the UK’s Ministry of Defence regained control of its accounts launched an investigation into the incident and apologized for the security breach.
We are aware of a breach of the Army’s Twitter and YouTube accounts and an investigation is underway.
— Ministry of Defence Press Office (@DefenceHQPress) July 3, 2022
The Army takes information security extremely seriously and is resolving the issue. Until their investigation is complete it would be inappropriate to comment further.
Apologies for the temporary interruption to our feed. We will conduct a full investigation and learn from this incident. Thanks for following us and normal service will now resume.
— British Army(@BritishArmy) July 3, 2022
At this time it is not clear how the attackers compromised the accounts simultaneously or if they were protected with two-factor authentication. In the latter case, threat actors could have obtained access to the account through SIM swapping attacks.
At this time it is not clear how the attackers compromised the accounts simultaneously or if they were protected with two-factor authentication. In the latter case, threat actors could have obtained access to the account through SIM swapping attacks. It is still unclear if someone has fallen victim to these scams proposed through the hacked accounts.
Follow me on Twitter: @securityaffairs and Facebook
[adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, British Army)
[adrotate banner=”5″]
[adrotate banner=”13″]