'ISIS' Hijacks Military Twitter, YouTube Accounts

The flag of the Islamic state.

The flag of the Islamic state.

Someone purporting to be "ISIS" hijacked the Twitter and YouTube accounts of U.S. Central Command today (Jan. 12), but it's unlikely the miscreants did any lasting damage, or were affiliated with the Islamic State at all.

"ISIS is already here, we are in your PCs, in each military base," read one tweet posted to the @CENTCOM account and grabbed by Engadget before Twitter suspended the account.

MORE: Anonymous Retaliates for Charlie Hebdo Attacks

Two pro-Islamic State videos appeared to have been posted to the U.S. Central Command YouTube page before it was wiped clean, according to a screen grab by Gizmodo, which showed the two clips alongside older ones showing cockpit footage of American airstrikes.

One tweet linked to a Pastebin page that read like something written by a kid pretending to be the Islamic State.

"AMERICAN SOLDIERS, WE ARE COMING, WATCH YOUR BACK. ISIS. #CyberCaliphate," it said. "In the name of Allah, the Most Gracious, the Most Merciful, the CyberCaliphate under the auspices of ISIS continues its CyberJihad. While the US and its satellites kill our brothers in Syria, Iraq and Afghanistan we broke into your networks and personal devices and know everything about you."

"You'll see no mercy infidels," it continued. "ISIS is already here, we are in your PCs, in each military base. With Allah's permission we are in CENTCOM now. We won't stop! We know everything about you, your wives and children. U.S. soldiers! We're watching you!"

Absent were any Arabic or Islamic terms beyond those with which an American who kept up on news would be familiar, or even the term "Islamic State." The group that now calls itself that dropped the ISIS name last June.

The posting also included links to what were said to be "confidential data from your mobile devices." Several websites that downloaded the documents said they appeared to be mostly older, publicly available Pentagon materials.

Hijacking organizational social-media feeds is usually a matter of obtaining — or guessing — usernames and passwords, credentials that are often shared among several people responsible for updating the account.

Previous Twitter hijacks by the Syrian Electronic Army (no friend of the Islamic State) involved phishing emails to staffers of the targeted organizations. All it takes is one person with access to the credentials to fall for the trick and give up the goods.

"While strong multifactor login controls exist, it is normal for shared PR accounts like this to lack that additional layer of security, making them an easier target," Trey Ford, global security strategist at Boston online-security firm Rapid 7, said in an emailed statement.

Ford additionally warned against downloading any of the purported stolen documents, worried that they may be "part of a targeted malware campaign targeting military analysts and their families."

Unlike the Syrian Electronic Army, the Islamic State has not been known to hijack its adversaries' social-media accounts.

A military spokesman told The New York Times that the Pentagon was addressing the issue.

U.S. Central Command is the cross-service Pentagon command that oversees all American military activity in the Middle East and Central Asia, including Iraq, Afghanistan and Pakistan.

Paul Wagenseil is a senior editor at Tom's Guide focused on security and gaming. Follow him at @snd_wagenseilFollow Tom's Guide at @tomsguide, on Facebook and on Google+.

TOPICS
Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Sunday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far