Categories: Tech

Twitter glitch allows CIA informant channel to be hijacked

A cyber-security researcher has exploited a glitch on the CIA's official Twitter account, to hijack a channel used for recruiting spies.

The US Central Intelligence Agency (CIA) account on X, formerly known as Twitter, displays a link to a Telegram channel for informants.

But Kevin McSheehan was able to redirect potential CIA contacts to his own Telegram channel.

"The CIA really dropped the ball here," the ethical hacker said.

The CIA is a US government organisation known for gathering secret intelligence information, often over the internet, from a vast network of spies and tipsters around the world

Its official X account, with nearly 3.5 million followers, is used to promote the agency and encourage people to get in touch to protect US national security.

Biggest fear

Mr McSheehan, 37, who lives in Maine, in the US, said he had discovered the security mistake earlier on Tuesday.

"My immediate thought was panic," he said.

"I saw that the official Telegram link they were sharing could be hijacked – and my biggest fear was that a country like Russia, China or North Korea could easily intercept Western intelligence."

  • US and Russian spy chiefs meet face-to-face
  • Inside the world's most top secret museum

At some point after 27 September, the CIA had added to its X profile page a link – https://t.me/securelycontactingcia – to its Telegram channel containing information about contacting the organisation on the dark net and through other secretive means.

The channel said, in Russian: "Our global mission demands that individuals be able to reach out to CIA securely from anywhere," while warning potential recruits to "be wary of any channels that claim to represent the CIA".

Image caption, Anyone clicking on the link was directed to Mr McSheehan's Telegram channel

But a flaw in how X displays some links meant the full web address had been truncated to https://t.me/securelycont – an unused Telegram username.

As soon as Mr McSheehan noticed the issue, he registered the username so anyone clicking on the link was directed to his own channel, which warned them not to share any secret or sensitive information.

"I did it as a security precaution," he said.

"It's a problem with the X site that I've seen before – but I was amazed to see the CIA hadn't noticed."

The CIA did not reply to a BBC News request for comment – but within an hour of the request, the mistake had been corrected.

This video can not be played

To play this video you need to enable JavaScript in your browser.

Media caption,

Watch: What is the dark web?

Share

Recent Posts

Dem elites accused of slapping small-town cops with ‘witch hunt’ fines twice their pay

close Video Border Patrol union praises Trump for resuming border wall construction: 'Amazing' what his…

40 minutes ago

Survivalist describes 4 ways Wyoming college professor missing in wilderness could have disappeared

close Video Survival expert weighs in on factors that may have contributed to college professor's…

40 minutes ago

Southern California community members return for first time to site where church burned down ahead of Easter

close Video LA-area congregation returns for first time to site where wildfires destroyed church Members…

7 hours ago

Protesters target Trump admin policies with march to White House, demonstrations throughout country

close Video Anti-Trump protesters turn out to rallies in Washington DC, across the country Protesters…

7 hours ago

5 alleged Tren de Aragua gang members charged in retail thefts, including 1 seen sobbing in police interview

close Video Interior Secretary Doug Burgum visits southern border amid military crackdown on illegal immigration…

7 hours ago

Motorist arrested after allegedly trying to run driver of Tesla off the road at high speeds: report

close Video ‘Global Day of Action’ sees protesters rally against Tesla, Elon Musk  Fox News…

7 hours ago