Every major cyberattack has a story behind it. A vulnerability no one patched. A phishing email someone clicked. A nation-state with a motive. Dark Perimeter goes beyond the headlines to explore the true stories of the hacks, breaches, and cyber operations that shaped history - told in narrative form for security professionals and curious minds alike. No guests, no panels, no filler. Just the story.
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
0:00
|
5:26
July 15th, 2020. Barack Obama, Joe Biden, Elon Musk, Apple, and Uber all tweeted the same thing: send Bitcoin, get double back.
It wasn't them. A seventeen-year-old in Florida had found a way inside Twitter's most protected systems — not by hacking the platform, but by paying someone already inside it.
For four hours, the most powerful accounts on earth belonged to a teenager on Discord.
The Breach Files: True cybercrime. Dramatized.
July 15, 2020, 4 17 in the afternoon, Eastern Time. The Twitter account of Barack Obama posts a message. I am giving back to my community due to COVID-19. All Bitcoins sent to my address below will be sent back doubled. Within minutes, Joe Biden, Elon Musk, Bill Gates, Apple, Uber, Jeff Bezos. The account of Michael Bloomberg, Kanye West. One after another, the most followed accounts on Twitter began posting identical Bitcoin addresses and identical promises. Twitter's trust and safety team saw what was happening immediately. They did the only thing they could. They locked every verified account on the platform, Blue Check, every account, from posting. For the first time in its history, Twitter went silent. In the time it took them to pull that switch, the scam had collected over $119,000 in Bitcoin. The attacker was not in a server room, he was not a state-sponsored intelligence operative. He was a 17-year-old in Tampa, Florida, sitting at a computer in his mother's house. His name was Graham Ivan Clark. His name online was Kirk. Alright, let's see who's working today. Weeks earlier, Kirk had found his way into a private Discord server, frequented by people who traded rare social media handles, short usernames that longtime users had abandoned, but that carried real value in certain communities. A two-letter Instagram handle, a single-word Twitter account. Kirk had been buying and selling them, and in that community he had learned something important. Some Twitter employees had access to an internal tool called the admin panel. It let them do anything to any account, reset passwords, change email addresses, disable two-factor authentication, take control. It had been built for legitimate purposes, helping users locked out of accounts, investigating abuse, responding to law enforcement requests. Kirk found a Twitter employee willing to sell access. I need access to the agent tools. I'll pay. How much? Name a number. The employee named a number. Kirk paid it in cryptocurrency. For a few hundred dollars, he had access to what internal Twitter staff called God Mode, a panel that could touch any account on the platform without restriction. His first moves were low profile. He used the admin panel to seize rare short handles and sell them to buyers who had been waiting for exactly this kind of opportunity. An account that had sat unused for years, a single word, worth thousands in the gray market. He ran that operation for days. Then he decided to get ambitious.
SPEAKER_01
My board is going to ask how a miner coordinated an attack at this scale and walked into our admin infrastructure without a single alarm tripping.
SPEAKER_03
He didn't use a zero day. He didn't break any cryptography. He paid someone who already had legitimate access.
SPEAKER_01
An insider.
SPEAKER_03
A phone agent.
SPEAKER_02
The Bitcoin scam on July 15th was not sophisticated. The crypto address was traced within hours. The platform was restored. The accounts were recovered. But the technical simplicity of the attack was precisely the point. Kirk had demonstrated something that no penetration test had ever surfaced: that the most powerful social media platform on Earth could be compromised not through its code, but through its people. The FBI trace was methodical. Kirk had made mistakes. He had used cryptocurrency wallets that could be linked back through earlier transactions. He had communicated through channels that, once subpoenaed, pointed directly to him. He had been 17, cocky, and certain that a Bitcoin transaction was untraceable.
SPEAKER_00
The subject was identified as Graham Ivan Clark, 17 years of age, residing in Hillsborough County, Florida. He was arrested on July 31, 2020, 16 days after the attack. Two co-conspirators were identified and charged separately: Mason Shepherd, 19 of Bognor Regis in the United Kingdom, and Nema Fazelli, 22 of Orlando, Florida.
SPEAKER_02
Because he was 17, Graham Clark was tried as a minor in Florida State Court. He pleaded guilty to fraud charges and was sentenced to three years in juvenile detention. A sentence that would have been measured in decades had he been tried as an adult under federal law. He was released at 20. Twitter disclosed in its post-incident report that the attackers had called Twitter employees directly, using information gathered through social engineering to impersonate the company's internal IT department and convince employees to hand over their credentials. The insider was not the only vector. Kirk had also called his way in. 130 accounts were accessed. Forty-five were used to post the Bitcoin scam. $119,000 collected. Four hours from first post to full platform lockdown. The employee who sold access was never publicly charged. Graham Clark served his time. When he was released, he was 20 years old. He was 17. For four hours on a Wednesday afternoon, he controlled the accounts of the most powerful people on earth. This is the breech files.