ALL NEWS

Here’s what the Twitter hack tells us about potential security risks of working from home

Jul 27, 2020, 7:01 AM

Twitter features...

said it would disable some features temporarily, making it more difficult for users to mindlessly retweet misleading claims. (Credit: Shutterstock Via CNN)

(Credit: Shutterstock Via CNN)

    (CNN) — The Twitter hack that compromised the accounts of Barack Obama, Kanye West and other figures earlier this month was one of the more prominent cybersecurity breaches in recent memory — and it was all the more dramatic as it played out live on the platform while users watched.

It was the first major breach reported since March, when many companies rapidly transitioned to remote working because of coronavirus.

For Twitter, the hack was certainly not a good look. CEO Jack Dorsey apologized for it on the company’s earnings call last week, saying: “Last week was a really tough week for all of us at Twitter, and we feel terrible about the security incident.”

For other companies, the hack could serve as a reminder that even at a moment when there is much else to worry about (like the economic recession and ongoing pandemic), cybersecurity threats are still an issue. It may be more true now than usual — experts say that having many people working from home presents unique security risks, especially given that many companies made the transition practically overnight.

It’s not clear whether remote working policies at Twitter, which has said it will allow some employees to continue working from home “forever” if they choose, had anything to do with the hack. But it’s something other companies should be aware of.

“The way (the transition to remote working) happened, instantly, there was no warning, and all of a sudden people were just told, ‘you’re not going back to work tomorrow,'” said Anu Bourgeois, an associate professor of computer science at Georgia State University. “Everybody became vulnerable at that point.”

Security risks from remote working

Only about 29% of workers had the option to work from home from 2017 to 2018, according to the most recent data available from the Bureau of Labor Statistics.

When coronavirus hit the United States, employers had to scramble to get a huge percentage of the country’s workforce to transition to remote working for the first time, a massive task that may have involved corner-cutting when it came to security.

There are a number of ways companies could have gone during the transition. In the hurry to keep employees safe but still maintain their workflow, companies might have given out laptops not equipped with the proper security software or asked them to use their own personal devices for work, Bourgeois said.

That issue was likely heightened for employees and families who can’t afford multiple devices and suddenly found themselves working from home while kids attended school remotely.

“They’re having to juggle different people using that device,” Bourgeois said. “Whereas at work you’re just one person, your kids may be having to use the device you use for work for their school or entertainment. You have that vulnerability of different people on your machine.”

Companies that were accustomed to having employees work only out of the office likely also had to develop new “access controls.” Whereas workers may have only been able to access their company’s servers and data from inside the office, they now may have to sign into a virtual private network (VPN) or other portal to securely access the information needed to do their jobs.

Deploying proper cybersecurity protocols for a remote workforce, “especially for a large scale company, is going to be really time consuming and difficult to do,” said Bourgeois.

She added that even with existing security software, companies could run into issues. Some security systems track employee habits — such as the normal days, times and duration of time that they typically access company systems — to identify potential hackers. But such systems may be confused by people’s changing work habits during the pandemic, and therefore could be less likely to catch breaches.

What we know about the Twitter hack

It’s unclear whether the Twitter hack had anything to do with remote working policies the company put in place in response to the pandemic.

Former Twitter employees examining the incident acknowledged that it’s a possibility, but there’s no evidence that Twitter relaxed its security to accommodate working from home. Twitter declined to comment on its remote work policies.

Twitter said the breach was the result of a coordinated “social engineering” attack that targeted workers who had administrative privileges, with the aim of taking control of the accounts.

Experts say social engineering may also be easier when people are working from home, where they may be distracted or let their guard down.

“You have people scrambling, in a different environment, and that mindset is not the same when you’re working from home versus the office,” Bourgeois said. “So many people are juggling their kids and are distracted and may be trying to quickly get through whatever task they need to get through. (They) may not be as sensitive to looking for these social engineering tactics, like phishing emails or phone calls.”

Some have also warned that hackers may try to exploit people’s fear of coronavirus in an attempt to carry out hacks or phishing attempts.

“As the world’s anxiety regarding coronavirus continues to escalate, the likelihood that otherwise more cautious digital citizens will click on a suspicious link is much higher,” the Electronic Frontier Foundation wrote in a March blog post.

The EFF cautioned people to look out for suspicious messages promising information or offers related to coronavirus, especially ones that sound too good to be true, like an offer to submit personal information in exchange for a free coronavirus vaccine.

For companies looking to avoid being the next target of an attack — in addition to implementing antivirus software and two-factor authentication — “the number one thing is education,” according to Bourgeois.

“Unless your employees are well versed in all of these different types of attacks and what to be aware of, it doesn’t matter what else you do, that person is vulnerable. Educating the workforce is key,” Bourgeois said.

–CNN’s Brian Fung contributed to this report.

The-CNN-Wire
™ & © 2020 Cable News Network, Inc., a WarnerMedia Company. All rights reserved.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

All News

trax train shown, fashion place trax station affected by police activity...

Emma Keddington

Man dead after TRAX incident

SALT LAKE CITY — The Utah Transit Authority has reported an incident Thursday night, at the Millcreek TRAX station.  According to UTA’s Carl Arky, a man in his 20s has died after being transported to the hospital in critical condition. He was struck by a northbound, blue line TRAX train at 2950 South, 200 West.  […]

4 hours ago

Iranian news agency FARS, citing local sources, reports multiple explosions were heard northwest of...

Hamdi Alkhshali and Artemis Moshtaghian, CNN

Israel has carried out a strike inside Iran, US official tells CNN

(CNN) — Israel has carried out a strike inside Iran, a US official told CNN, a move that threatens to push the region deeper into conflict. The target is not nuclear, the official said. Iran’s air defense systems were activated in several locations after three explosions were heard close to the airport and an army […]

5 hours ago

Chad Daybell, left, is pictured in a courtroom in St. Anthony, Idaho, on Aug. 3, 2020, while Lori V...

Emily Ashcraft, KSL.com

Chad Daybell and Lori Vallow Daybell used ‘castings’ to pray for spouses’ deaths, ex-friend testifies

Melanie Gibb, the former best friend of Lori Vallow Daybell, testified Thursday about multiple disturbing conversations she had.

5 hours ago

A car is filled at a gas pump in Sandy on Tuesday, March 19, 2024. Hurricane season could affect ga...

Britt Johnson

Hurricane season could mean bad news for Utah gas prices

Hurricane season is expected to be intense this year, and while none of them should hit Utah rising gas prices probably will. 

6 hours ago

...

Steve Salles

KSL Movie Show review: ‘The Ministry of Ungentlemanly Warfare’ is pure gung-ho

In this KSL Movie Show review, host Steve Salles dives into 'The Ministry of Ungentlemanly Warfare,' which insists that you have a good time at the expense of some bad guys.

6 hours ago

FILE -- Ducks and geese swim in Spring Lake in Payson on Thursday, Jan. 27, 2022. Millions have bee...

Britt Johnson

Millions raised for habitat restoration in the state

It's been a record breaking fundraising year for habitat restoration here in Utah.  The Utah Conservation Permit Program raised a record $4.8 million.

7 hours ago

Sponsored Articles

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

front of the Butch Cassidy museum with a man in a cowboy hat standing in the doorway...

Bear Lake Convention and Visitors Bureau

Looking Back: The History of Bear Lake

The history of Bear Lake is full of fascinating stories. At over 250,000 years old, the lake has seen generations of people visit its shores.

silhouette of a family looking over a lake with a bird in the top corner flying...

Bear Lake Convention and Visitors Bureau

8 Fun Activities To Do in Bear Lake Without Getting in the Water

Bear Lake offers plenty of activities for the whole family to enjoy without having to get in the water. Catch 8 of our favorite activities.

Here’s what the Twitter hack tells us about potential security risks of working from home