ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Congressman Steny Hoyer Twitter impersonation attack

By | January 25, 2011, 11:19pm PST

The twitter account LeaderHoyer, as recently as a few hours ago linked to by the official congressional web site of Maryland Congressman Steny Hoyer as his Twitter account, started expressing some unusually caustic views during the President’s State of the Union Address.

The twitter account @leaderhoyer on 1/26/11.

The twitter account @leaderhoyer on 1/26/11.

The tweets are obviously not Congressman Hoyer, however the account was likely not “hacked” as a few on Twitter have speculated. The LeaderHoyer account was definitely that of Congressman Steny Hoyer at one time, for example here is how it appeared on July 7th of last year:

The leaderhoyer account on 7/7/2010.

The leaderhoyer account on 7/7/2010.

But comparing the LeaderHoyer account now with its appearance last year, there are a number of inconsistencies. Last year the account showed as “Verified”, Twitter’s method of stating the authenticity of famous peoples’ accounts, now it does not. The follower account tonight appears as 50, last year he had some 2,000+ followers. Finally, the account LeaderHoyer shows a creation date of January 14th, 2011, while the congressman has been on Twitter since the early part of 2009.

So What Happened?

Congressman Hoyer was recently reappointed to the role of House Minority Whip, leaving the role he had from 2007 to 2011 of House Majority Leader. Likely as a result of this, he modified the name of his twitter account from LeaderHoyer to WhipHoyer, an account that is verified, shows tweets you would expect from a congressman’s account, and has 5,734 followers. When the LeaderHoyer account was abandoned, it became available as a Twitter account name someone could sign up for, and in a display of patient planning a prankster signed up for the account on January 14th, and then waited for the 25th when Hoyer’s account would get maximum exposure (many constituents look at their congress member’s online communications to see their statement following the President’s speech) to start tweeting.

The congressman’s web site probably had an old link under the twitter icon, part of a bank of social media links in the right column of the official web site that disappeared later in the evening. Ostensibly that was the result of someone on the congressman’s staff, or someone responsible for the web site, becoming aware of the link to the now rogue twitter account.

The whole exercise is a lesson in carefully planning and coordinating social media changes, as even the prankster not so subtly expressed in a tweet: “This is what happens when political offices pay for high-priced, money-sucking ‘social media’ firms that have no clue what they are doing.” If the person perpetuating the hoax had posted tweets that were less ludicrous, the updates may have passed for those of the congressman for a while. For a politician, controlling communications with constituents is paramount.

But Twitter might consider a change here as well. Obviously accounts that are verified, but change names making what was once a verified account name available during user registration, are more of a target for people wishing to impersonate a well known person. Perhaps Twitter should lock those original names after a name change for a longer period of time, since they went through the Twitter verification program.

The timing of the attack is reminiscent of last year’s mass defacement of congressional web sites following the State of the Union address by the Brazilian defacement team the Red Eye Crew.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Daniel Kennedy leads initiatives in policy and operational security management, directs strategy on risk assessment and certification, and is head of business continuity planning and disaster recovery at Praetorian Security Group, LLC.

Disclosure

Daniel Kennedy

Daniel Kennedy is a part owner of the information security consulting firm Praetorian Security Group, LLC. He has some stock in Bank of New York, and a standard 401k invested in various mutual funds.

Biography

Daniel Kennedy

Daniel Kennedy leads initiatives in policy and operational security management, directs strategy on risk assessment and certification, and is head of business continuity planning and disaster recovery at Praetorian Security Group, LLC.

Prior to Praetorian Security Group, Daniel was the Global Head of Information Security at D.B. Zwirn & Co. where he managed the firm's information security program. He was specifically responsible for the development, implementation, and maintenance of the firm's information security policies. He also managed security metrics reporting, the security awareness and education program, security incident response, security audit, and developing the firm's security technology strategy. In this role he worked closely with the firm's CIO, COO, head of compliance, head of legal, head of infrastructure, head of client services, and overseas IT managers.

Prior to D.B. Zwirn, Daniel was Vice President and Program Manager for the application security program at Pershing LLC, a division of the Bank of New York. Daniel's responsibilities included management of the firm's application security program, coordination of application vulnerability assessments and penetration testing, application security training, documentation of secure coding guidelines, and development of the firm's application security SDLC. He was the primary liaison for application security concerns between application development and teams such as the Information Security Office, Internal Audit, Information Risk Management (IRM), and the business teams. He served on several firm committees including the Infrastructure Security Workgroup, Security Architecture, and chartered and chaired the firm's Application Security Council, an interdisciplinary group consisting of application developers and information security subject matter experts.

His previous positions at Pershing included development management and systems' engineering positions building the firm's web applications for facilitating online brokerage. He has also been employed at Donaldson, Lufkin, & Jenrette Inc. in a technology analyst role for the Treasury area.

Daniel holds a Masters of Science degree in Information Systems from Stevens Institute of Technology, a Masters of Science in Information Assurance from Norwich University, and a Bachelors of Science in Information Management and Technology from Syracuse University. He is certified as a CEH (Certified Ethical Hacker) from the EC-Council, a CISSP, and has a NASD Series 7 license.

You can also follow him on Twitter as well as the blog Praetorian Prefect.

22
Comments

Join the conversation!

Just In

RE: Congressman Steny Hoyer Twitter impersonation attack
krispeters10 18th Oct
@lovedong This can be very dangerous if you have a good reputation on twitter and someone using your account without you knowing it. I think you just have to be extra careful. p90x
0 Votes
+ -
OMG CYber terrorism!!
guihombre 26th Jan 2011
Meh if it wasn't LeaderHoyer, they would have created an account StenyHoyer, or LeaderStenyHoyer...

We're talking about a joker playing to an insignificant audience here.
@guihombre I think the difference here is that the account actually did belong to Hoyer at one point, and was still linked to by his congressional web site.
Shortly after President Obama???s State of the Union address, constituents visiting the web sites of Congressional representatives like Charles Gonzalez (20th District of Texas), Spencer Bachus (Alabama???s 8th District), and Brian Baird (Washington???s 3rd District) were presented with a defacement message from the Red Eye Crew that as of 4:10 am EST remains up on their web sites. All of the sites affected are in the house.gov domain, but not every congressional site in the domain is defaced. sell your mobile
The Mobius combination case and solar charger includes a standby switch that prevents power from being fed into the phone during the charging process. how can you make your hair grow faster
In the future, my PC will be in my pocket, clothing or implanted - essentially just a very smartphone. I'll be using either glasses with transparency and HUD as the phone display and making gestures to be picked up by the Kinect sensors in my glasses. If I want a keyboard, one will appear, but a lot of computer interaction will be via voice and gestures. online advertising
The whole exercise is a lesson in carefully planning and coordinating social media changes, as even the prankster not so subtly expressed in a tweet: ?This is what happens when political offices pay for high-priced, money-sucking ?social media? firms that have no clue what they are doing.? If the person perpetuating the hoax had posted tweets that were less ludicrous, the updates may have passed for those of the congressman for a while. For a politician, controlling communications with school girl pictures constituents is paramount.
Thank you! Thank you! chanel bags
@lovedong This can be very dangerous if you have a good reputation on twitter and someone using your account without you knowing it. I think you just have to be extra careful. p90x
@guihombre I completely agree with you Tasmania Hospitality
Is T-Mobile's touchscreen-less, OS 7-running BlackBerry Curve 9360 the austere smartphone choice for busy and budget-minded professionals and consumers? offshore company incorporation
@guihombre Yes the only thing is is that we are not laughing about it Buy Twitter Followers
@guihombre oh american politics are so much fun to watch Life Coach
The congressman???s web site probably had an old link under the twitter icon, part of a bank of social media links in the right column of the official web site that disappeared later in the evening. Ostensibly that was the result of someone on the congressman???s staff, or someone responsible for the web site African Mango, becoming aware of the link to the now rogue twitter account.
I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate! nccma cooler
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post. this thread is amazing i like your work and i appreciate you that you have share a useful stuff thanks for sharing the i shop abatwa
I used to be more than happy to seek out this internet-site.I wanted to thanks in your time for this glorious read!! I positively enjoying each little bit of it and I have you bookmarked to check out new stuff you weblog post.Bookmarking now thanks please consider a follow up post. power sa shop
I think the representation of this article is actually superb one. This is my first visit to your site. Thanks a lot and keep sharing the information. Keep updating the information for all of us. Thanks ZDNet Government was launched as the brand's first industry vertical, with a mission to cater to IT professionals in the public secto I agree with your post. However, do you have any sources I can cite for my paper wheel car com bury
Well welcome, hopefully you can become a vital member of the community and really help to push far ahead of google. Which Im sure the development team would love. This will of course earn you alot points too and get you on the leaders board. z d n e t t h a n k Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas.
This is my first visit to z d n e t site. Thanks a lot and keep sharing the information. Keep updating the information for all of us.how can i clean up, because i don???t know why it seems my skeen has to fat i get the glasses dirty every day.i search y a h o o Very good quality indeed. I surely recommend it. The template used in their site is also great.
Fantastic news about the new release.I positively enjoying each little bit of it and I have you b o o k m a r k e d to check out new stuff you weblog post.Im not sure i come to an agreement with you on every level, howevor it absolutely was a good posting, many thanks for taking the time to put up your ideas
Good day to confirm this comment I would appreciate T h e b e s t o f Z D N e t d e l i v e r e d your website very nice to everyone Yes, Oracle is the only one with shared-disk architecture, but that is there advantage. It means you can add or remove nodes and the database lives on. In a shared nothing architecture, if you lose a node, you lose the system. I'm sure Oracle appreciates EMC highlighting their advantage.I also desire to signal in your RSS feeds. Thank you as soon as once again and maintain up the great operate Awesome post! Thank you very much || thanks for nice content this is really benefit to me.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix