Case File

The 17-Year-Old Who Hijacked Twitter's Biggest Accounts

How a teenager orchestrated a massive cryptocurrency scam targeting Elon Musk, Bill Gates, and the world's most influential figures

🇺🇸 American

Published June 6, 2025

A computer screen displaying a Twitter interface with prominent hacked account names like Obama and Musk, showing unfamiliar tweets about Bitcoin, exemplifying the massive 2020 Twitter security breach by Graham Ivan Clark.
EVIDENCE

Case Details

Quick Facts

Case Status
Solved
Location
Tampa, Florida, USA

Quick facts

LocationTampa, Florida, USA

On July 15, 2020, Twitter experienced one of its most humiliating security breaches when 130 high-profile accounts fell under the control of attackers in a matter of hours. The perpetrators used the compromised accounts to promote a "double your bitcoin" scam, stealing thousands of dollars in cryptocurrency before Twitter regained control of the platform.

At the center of the attack was Graham Ivan Clark, just 17 years old at the time. Working alongside accomplices Mason Sheppard, 19, and Nima Fazeli, 22, Clark orchestrated a social engineering attack so sophisticated that it bypassed Twitter's security infrastructure entirely.

The attackers' method was deceptively simple but devastatingly effective. Rather than attempting to crack complex passwords or exploit obscure software vulnerabilities, they targeted Twitter employees directly. The team impersonated Twitter's IT help desk, convincing employees that they needed to verify their credentials. The attackers directed staff to a phishing portal designed to mimic Twitter's legitimate VPN login page. Once employees entered their credentials, the attackers gained access to the company's internal systems.

Timeline

1 January 2019

SIM-swap attack on investor

Clark steals 164 Bitcoins from angel investor Gregg Bennett through SIM swapping

15 July 2020

Twitter hack begins

At 20:00 UTC the takeover of 130 high-profile Twitter accounts begins

15 July 2020

Bitcoin scam runs

Over 320 people transfer a total of more than 117,000 dollars in Bitcoin

15 July 2020

Twitter responds

After two hours the fraudulent tweets are deleted and the accounts secured

31 July 2020

Clark arrested

Graham Ivan Clark is arrested in Florida

1 March 2021

Plea deal and sentence

Clark pleads guilty and is sentenced to three years in prison

With internal access secured, the attackers turned their attention to the platform's most famous users. They hijacked accounts belonging to Elon Musk, Bill Gates, Kanye West, Kim Kardashian West, Barack Obama, and many others. The compromised accounts began posting identical messages promoting a cryptocurrency scheme: send bitcoin and receive double the amount in return—a classic advance-fee scam that has defrauded countless victims over the years.

However, the financial scam was only part of the perpetrators' objective. Simultaneously, they were selling "OG" (original) Twitter usernames—coveted early accounts with short, simple handles—on the OGUsers platform for bitcoin. These original usernames are highly prized in online communities and can command significant prices.

The attack lasted for several hours, beginning around 3 a.m. and continuing until Twitter's security team regained control at approximately 6:05 p.m. During that window, the attackers managed to steal a substantial amount in cryptocurrency before the platform's defenses shut down the operation.

The 2020 breach was not Clark's first foray into cybercrime. In 2019, he had been involved in a SIM swap attack—a technique where hackers convince mobile carriers to transfer a victim's phone number to a device they control—that targeted Seattle angel investor Gregg Bennett. That attack resulted in the theft of 164 bitcoins, worth millions of dollars at the time.

Law enforcement eventually identified and prosecuted the perpetrators. Graham Ivan Clark, despite his age, was convicted as a felon for his role in orchestrating the attack. His case highlighted a troubling reality: sophisticated cybercrimes are not always committed by experienced adult hackers operating from foreign countries, but sometimes by tech-savvy teenagers working from their homes.

The Twitter breach exposed critical weaknesses in how tech companies protect their internal systems. While the platform's public-facing security measures might be robust, the human element—employees who can be socially engineered into compromising their own credentials—remains a significant vulnerability. The incident prompted Twitter and other major platforms to reassess their employee security training and access controls.

For the broader cybersecurity community, the 2020 Twitter attack served as a stark reminder that the most sophisticated attacks often rely on social engineering rather than technical wizardry. A convincing phone call or email can sometimes accomplish what months of hacking attempts cannot.

Sources

https://www.dfs.ny.gov/Twitter_Report

https://en.wikipedia.org/wiki/Graham_Ivan_Clark

Ask about this case

Answers from KrimiNyt's coverage only

Follow this case

Get an email when a new documentary, podcast or book about The 17-Year-Old Who Hijacked Twitter's Biggest Accounts appears, or when a verdict is reached.

Share this post: