Our Snopes account was hacked on X (formerly twitter) and we got locked out for six weeks. We finally just got it back!
See the full story in the comments below for what we had to do to get someone/anyone at X to help us.
Our Snopes account was hacked on X (formerly twitter) and we got locked out for six weeks. We finally just got it back!
See the full story in the comments below for what we had to do to get someone/anyone at X to help us.
From Snopes CEO
1/8
On Jan 31st, one of our employees said they couldn’t log in to our Snopes X account. I checked our site email and noticed that a minute earlier, we received an email from X saying someone new logged into our Snopes account. I didn’t recognize the location and then I saw another email that came directly after saying “X two-factor authentication is good to go”.
That’s when panic set in.
8/8
90 minutes later he gave us confirmation from support saying our account was hacked and they are resetting it for us. A few minutes later we had our Snopes account back!
In summary, always use two-factor authentication. We left it off because we had multiple employees logging into the account, but clearly it’s not worth the risk.
X has the worst customer support I’ve ever seen, even if you pay $1,000/month you can’t email them.
Grok did help save the day by pointing us to John Stoll.
@snopes it's trivial to setup 2fa across multiple devices using the code method with proton pass, Google auth, or virtually anything else. Bitlocker I believe has a corp management system.
Can bad actors still compromise you? Sure. Is insider risk still bad? Absolutely. Is it better than no 2fa? Oh yeah.