Twitter link glitch allows CIA contact line to be hijacked by hacker

.

Central Intelligence Agency seal, CIA seal, logo
FILE – The seal of the Central Intelligence Agency at CIA headquarters in Langley, Va., on April 13, 2016. President Joe Biden will visit the CIA at a time when his administration’s support for Ukraine has pushed the normally secretive intelligence agencies into the limelight. Biden on Friday will commemorate the CIA’s 75th anniversary since its founding after World War II. (AP Photo/Carolyn Kaster, File) Carolyn Kaster/AP

Twitter link glitch allows CIA contact line to be hijacked by hacker

Video Embed

A minor glitch was found by a hacker on the CIA‘s official account on X, formerly named Twitter, that foreign nations could hijacked.

Kevin McSheehan, a cybersecurity researcher, reported finding a security link on the platform’s social profile that could have been used to hijack a secure line. The CIA has a link to a Telegram account used to speak with informants on its platform. The link, which is https://t.me/securelycontactingcia, was added on Sept. 27 and linked to a private forum for providing tips to the CIA. The X account unintentionally shortened the link to https://t.me/securelycont, an unused Telegram username that could have been claimed by a third party.

WHAT TRUMP CAN AND CAN’T SAY NOW THAT HE’S UNDER A GAG ORDER IN CRIMINAL COURT

“The CIA really dropped the ball here,” McSheehan told the BBC. A foreign nation could have taken that Telegram tag and used it to acquire intelligence intended for the CIA, the researcher argued.

McSheehan registered the username himself while redirecting it to his channel. He also posted a message warning to visitors not to share secret information across the channel.

CLICK HERE TO READ MORE FROM THE WASHINGTON EXAMINER

“I did it as a security precaution,” he said. “It’s a problem with the X site that I’ve seen before — but I was amazed that the CIA hadn’t noticed.”

X and the CIA did not respond to requests for comment from the Washington Examiner. The original link, however, has been corrected.

© 2023 Washington Examiner

Related Content