Case File

How Twitter's Own CEO Got SIM Swapped

It is one thing to warn clients that SIM swapping is a real threat. It is another to point to the CEO of a major social media platform having his own account hijacked by exactly that method, in full public view.

What Happened

August 2019. Jack Dorsey, then CEO of Twitter, watched his own verified account post a stream of offensive messages he had never written. Twitter later confirmed the cause: his phone number had been ported to an attacker's SIM card through what the company called a security oversight at his mobile carrier.

The Damage Caused

The account was compromised for roughly 20 minutes before Twitter regained control, plenty of time for offensive content to reach millions of followers under Dorsey's name. The financial damage was limited. The reputational and structural damage was not. It forced a public reckoning with the fact that even the platform's own CEO had left himself exposed to an attack any of its users could suffer.

What Caused the Breach

Twitter had a feature (still active in some regions) called Cloudhopper that lets a linked phone number post directly by text message, without logging into the app or website at all. It exists for convenience in low-connectivity regions. It also means anyone who controls that phone number can post as the account holder, no password required.

Once attackers had Dorsey's number through the carrier-side SIM swap, that feature became the entire attack. No password was reset. No account recovery flow was triggered. The phone number alone was sufficient.

What Could Have Been Done to Avoid the Issue

Twitter's own response was instructive. It suspended SMS-to-tweet functionality in the immediate aftermath, then reinstated it only in regions that depend on it, a tacit admission that convenience and security were in direct tension on this feature. For anyone in a public-facing or executive role, the lesson generalises well beyond Twitter: any account feature that trusts a phone number as a substitute for a password deserves the same scrutiny as the password itself.

Removing SMS-based recovery and posting features wherever a platform allows it, then replacing SMS two-factor authentication with an authenticator app or hardware key, closes the specific gap this attack relied on. It also removes a mobile carrier, a party with no stake in a given account's security, from the list of things that has to go right to keep that account safe.

Every security measure involves a trade-off between protection and convenience. Where that balance should sit depends on the resources a realistic attacker would bring to bear against you specifically. For most people, a handful of consistent habits closes the majority of that gap. For those whose assets or profile make a determined, well-funded attacker plausible, a more considered approach becomes worth the investment.

At Executive Privacy Advisors, we build that approach around your specific threat profile rather than a generic checklist. We extend the same thinking to your whole household, not just one set of accounts.

Worried about digital security at home?

Request Audit

Published by Executive Privacy Advisors.

This article is for general informational purposes only and does not constitute security, legal or risk advice. Services described are subject to assessment, licensing and availability in your area. Your circumstances may differ and you should seek a professional assessment before making decisions.

← Back to all Case Files