TECHNOLOGY

Here’s what the Twitter hack tells us about potential security risks of working from home

Jul 27, 2020, 7:01 AM
Twitter features...
said it would disable some features temporarily, making it more difficult for users to mindlessly retweet misleading claims. (Credit: Shutterstock Via CNN)
(Credit: Shutterstock Via CNN)

    (CNN) — The Twitter hack that compromised the accounts of Barack Obama, Kanye West and other figures earlier this month was one of the more prominent cybersecurity breaches in recent memory — and it was all the more dramatic as it played out live on the platform while users watched.

It was the first major breach reported since March, when many companies rapidly transitioned to remote working because of coronavirus.

For Twitter, the hack was certainly not a good look. CEO Jack Dorsey apologized for it on the company’s earnings call last week, saying: “Last week was a really tough week for all of us at Twitter, and we feel terrible about the security incident.”

For other companies, the hack could serve as a reminder that even at a moment when there is much else to worry about (like the economic recession and ongoing pandemic), cybersecurity threats are still an issue. It may be more true now than usual — experts say that having many people working from home presents unique security risks, especially given that many companies made the transition practically overnight.

It’s not clear whether remote working policies at Twitter, which has said it will allow some employees to continue working from home “forever” if they choose, had anything to do with the hack. But it’s something other companies should be aware of.

“The way (the transition to remote working) happened, instantly, there was no warning, and all of a sudden people were just told, ‘you’re not going back to work tomorrow,'” said Anu Bourgeois, an associate professor of computer science at Georgia State University. “Everybody became vulnerable at that point.”

Security risks from remote working

Only about 29% of workers had the option to work from home from 2017 to 2018, according to the most recent data available from the Bureau of Labor Statistics.

When coronavirus hit the United States, employers had to scramble to get a huge percentage of the country’s workforce to transition to remote working for the first time, a massive task that may have involved corner-cutting when it came to security.

There are a number of ways companies could have gone during the transition. In the hurry to keep employees safe but still maintain their workflow, companies might have given out laptops not equipped with the proper security software or asked them to use their own personal devices for work, Bourgeois said.

That issue was likely heightened for employees and families who can’t afford multiple devices and suddenly found themselves working from home while kids attended school remotely.

“They’re having to juggle different people using that device,” Bourgeois said. “Whereas at work you’re just one person, your kids may be having to use the device you use for work for their school or entertainment. You have that vulnerability of different people on your machine.”

Companies that were accustomed to having employees work only out of the office likely also had to develop new “access controls.” Whereas workers may have only been able to access their company’s servers and data from inside the office, they now may have to sign into a virtual private network (VPN) or other portal to securely access the information needed to do their jobs.

Deploying proper cybersecurity protocols for a remote workforce, “especially for a large scale company, is going to be really time consuming and difficult to do,” said Bourgeois.

She added that even with existing security software, companies could run into issues. Some security systems track employee habits — such as the normal days, times and duration of time that they typically access company systems — to identify potential hackers. But such systems may be confused by people’s changing work habits during the pandemic, and therefore could be less likely to catch breaches.

What we know about the Twitter hack

It’s unclear whether the Twitter hack had anything to do with remote working policies the company put in place in response to the pandemic.

Former Twitter employees examining the incident acknowledged that it’s a possibility, but there’s no evidence that Twitter relaxed its security to accommodate working from home. Twitter declined to comment on its remote work policies.

Twitter said the breach was the result of a coordinated “social engineering” attack that targeted workers who had administrative privileges, with the aim of taking control of the accounts.

Experts say social engineering may also be easier when people are working from home, where they may be distracted or let their guard down.

“You have people scrambling, in a different environment, and that mindset is not the same when you’re working from home versus the office,” Bourgeois said. “So many people are juggling their kids and are distracted and may be trying to quickly get through whatever task they need to get through. (They) may not be as sensitive to looking for these social engineering tactics, like phishing emails or phone calls.”

Some have also warned that hackers may try to exploit people’s fear of coronavirus in an attempt to carry out hacks or phishing attempts.

“As the world’s anxiety regarding coronavirus continues to escalate, the likelihood that otherwise more cautious digital citizens will click on a suspicious link is much higher,” the Electronic Frontier Foundation wrote in a March blog post.

The EFF cautioned people to look out for suspicious messages promising information or offers related to coronavirus, especially ones that sound too good to be true, like an offer to submit personal information in exchange for a free coronavirus vaccine.

For companies looking to avoid being the next target of an attack — in addition to implementing antivirus software and two-factor authentication — “the number one thing is education,” according to Bourgeois.

“Unless your employees are well versed in all of these different types of attacks and what to be aware of, it doesn’t matter what else you do, that person is vulnerable. Educating the workforce is key,” Bourgeois said.

–CNN’s Brian Fung contributed to this report.

The-CNN-Wire
™ & © 2020 Cable News Network, Inc., a WarnerMedia Company. All rights reserved.

Today’s Top Stories

Technology

space radio...
Elizabeth Weiler

USU making history with a radio entering the lunar orbit

LOGAN, Utah — Utah State University has successfully sent a radio, created by Utah State University’s Space Dynamics Laboratory into the orbit of earth’s moon.  The deep space radio is named Iris, after the Greek mythological goddess, daughter of Thaumas and Electra and messenger of the gods. The radio made its way into the orbit via a CubeSat […]
2 days ago
In this image provided by NASA, the Earth and its moon are seen from NASA's Orion spacecraft on Mon...
Jackie Wattles, CNN

NASA’s Orion reaches record-breaking distance from Earth

NASA confirmed that Orion had reached the midpoint of its uncrewed mission around the moon — about 270,000 miles (434,523 kilometers) from Earth.
3 days ago
Former US President Donald Trump's Twitter account has been reinstated on the platform....
Clare Duffy and Paul LeBlanc, CNN

Elon Musk restores Donald Trump’s Twitter account

Former US President Donald Trump's Twitter account has been reinstated on the platform.
13 days ago
With employees with the company, the future of Twitter is in uncertain. Photo credit: Justin Sulliv...
Oliver Darcy, CNN Business

Inside Twitter as ‘mass exodus’ of staffers throws platform’s future into uncertainty

With employees leaving the company, the future of Twitter is uncertain.
14 days ago
NASA's Space Launch System (SLS) rocket with the Orion spacecraft aboard is seen on Nov. 12 at NASA...
Jackie Wattles, CNN

Historic moon mission troubleshoots fuel leak issue hours before launch

The Artemis I mission to the moon could finally take place this week.
17 days ago
FILE - A Tesla owner charges his vehicle at a charging station in Topeka, Kan., Monday, April 5, 20...
Peter Valdes-Dapena, CNN Business

Tesla officially makes its charging standard available to other companies

Tesla has invited other automakers to build cars with charging ports that can work with Tesla's charging format and for other charging companies to add Tesla-style plugs to their chargers.
20 days ago

Sponsored Articles

Spicy Homemade Loaded Taters Tots...
Macey's

5 game day snacks for the whole family (with recipes!)

Try these game day snacks to make watching football at home with your family feel like a special occasion. 
Happy joyful smiling casual satisfied woman learning and communicates in sign language online using...
Sorenson

The best tools for Deaf and hard-of-hearing workplace success

Here are some of the best resources to make your workplace work better for Deaf and hard-of-hearing employees.
Team supporters celebrating at a tailgate party...
Macey's

8 Delicious Tailgate Foods That Require Zero Prep Work

In a hurry? These 8 tailgate foods take zero prep work, so you can fuel up and get back to what matters most: getting hyped for your favorite
christmas decorations candles in glass jars with fir on a old wooden table...
Western Nut Company

12 Mason Jar Gift Ideas for the 12 Days of Christmas [with recipes!]

There are so many clever mason jar gift ideas to give something thoughtful to your neighbors or friends. Read our 12 ideas to make your own!
wide shot of Bear Lake with a person on a stand up paddle board...

Pack your bags! Extended stays at Bear Lake await you

Work from here! Read our tips to prepare for your extended stay, whether at Bear Lake or somewhere else nearby.
young boy with hearing aid...
Sorenson

Accommodations for students who are deaf and hard of hearing

These different types of accommodations for students who are deaf and hard of hearing can help them succeed in school.
Here’s what the Twitter hack tells us about potential security risks of working from home