Hackers takeover Twitter accounts to spread fake news

It's called "DoubleSwitch."
 By 
Kerry Flynn
 on 
Hackers takeover Twitter accounts to spread fake news
Credit: JAAP ARRIENS/NURPHOTO/GETTY

Sounds like my worst nightmare.

Hackers are taking over Twitter accounts and spreading misinformation in a new kind of attack, The Verge reported, citing digital rights group Access Now. The accounts of human rights activists and journalists in Venezuela and Bahrain have been the targets.

The hack, called "DoubleSwitch" involves taking over the account and then switching the username. The hacker then creates a new account under the original username and oftentimes uses the same profile picture and display name, according to The Verge.

Because of this "DoubleSwitch," the original user is unable to recover the original account. They do not know the old account's new account name and their original account name is now registered to the hacker.

Why the takeover? Hackers are using these accounts to spread fake news. Of course, the followers of the original account are not transferred over. But still, the original name is lost and can warrant confusion from former followers.

Twitter was able to recover two of the accounts cited by Access Now. The company did not immediately respond to a request for comment.

One key solution to make sure this doesn't happen to activate two-factor authentication, where you have to use another device to approve your sign-in.

Facebook, which is not seeing the same problems according to Access Now, did respond to The Verge and to Mashable, citing two-factor as a solution.

"We recognize the risk of malicious actors seeking to mislead people. For our part, we are taking a multifaceted approach to help mitigate these risks, such as building a combination of automated and manual systems to block accounts used for fraudulent purposes, and we continue to encourage people to use two-factor authentication," a Facebook spokesperson wrote in an emailed statement.

"As Access states, two-factor (multi-factor) authentication is an important security feature that Facebook offers to people that makes it much harder for an account to be compromised in the first place," the statement continued.

However, two-factor isn't a perfect solution. Some activists do not like to share and associate personally-identifiable information with their accounts.

Mashable Image
Kerry Flynn

Kerry Flynn is a business reporter for Mashable covering the tech industry. She previously reported on social media companies, mobile apps and startups for International Business Times. She has also written for The Huffington Post, Forbes and Money magazine. Kerry studied environmental science and economics at Harvard College, where she led The Harvard Crimson's metro news and design teams and played mellophone in the Band. When not listening to startup pitches, she runs half-marathons, plays with puppies and pretends to like craft beer.

Mashable Potato

Recommended For You
AdultFriendFinder profiles: 3 tips to sort legit from fake
By Jack Dawes
AFF logo on phone

Iran-linked hackers launch cyberattack against U.S. medtech company Stryker
Stryker logo on medical equipment

How hackers are stealing millions from ATMs, FBI warns
a card being inserted into an atm

Elon Musk found liable for defrauding Twitter investors
Elon Musk arrives at federal court on March 4, 2026 in San Francisco, California.


Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

NYT Connections hints today: Clues, answers for April 4, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone

Wordle today: Answer, hints for April 4, 2026
Wordle game on a smartphone

Google launches Gemma 4, a new open-source model: How to try it
Google Gemma
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!