Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Social Engineering Your Employees Beats Hacking Your Systems

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by phoning Twitter employees and tricking them into handing over login details. Social engineering often beats technology.

Why people are the target

Attackers go where the defenses are weakest. A convincing phone call from "IT support" can get past firewalls, password rules and even some forms of multi-factor authentication. Employees with access to powerful internal tools are especially valuable targets.

The business impact

  • Loss of control over customer accounts, systems or data.
  • Public embarrassment when misuse is visible.
  • Regulatory scrutiny of access controls and security leadership.

Questions to ask your team

  • How many employees have access to powerful administrative tools?
  • Is that access permanent, or granted only when needed?
  • Would our sign-in protection stop a fake login page that relays codes in real time?
  • How do employees verify that a call from "IT" is genuine?

What good looks like

Few administrators, time-limited access, phishing-resistant MFA for anyone with admin rights, and a simple verification rule: IT never asks for codes or passwords over the phone.

The decision

Ask how many people have standing administrative access today. Reducing that number — and making access temporary — directly limits what social engineering can achieve.

twitter hack 2020 impactTwitter admin tool hack2020

More on this story