Hacking the NASA Twitter Account

happygeek 0 Tallied Votes 772 Views Share

The 48,727 followers of the NASA Astronaut account on Twitter expect to hear about updates on astronaut activity and get some personal insight from the astronauts themselves. They probably were not expecting to be bombarded by spacemen offering to sell them plasma and LCD flat-screen TVs at bargain prices however.

Yet that is exactly what happened yesterday during a totally bizarre couple of hours when the official Nasa_Astronauts account at Twitter was hacked by a bunch of very terrestrial spammers.

A series of tweets, purporting to come from the astronauts themselves, were published which all appeared to offer either TV sets or TV accessories for sale via auction. The tweets included a shortened bit.ly link which ended up on eBay where the goods were being auctioned.

But things take another twist when you follow the links to those auction items, as I did, because rather than being actual television sets for sale what was being auctioned were 'wholesale lists' of TVs for sale. Such listings are often used as scams to attract bidders who see the picture of a big TV and the words Plasma Flat-Screen TV and a very low buy-it-now price, and ignore the description detail. It didn't take too long for Houston to realise there was a problem, and a post soon appeared that stated: "Our apologies for the odd Twitter behavior earlier. We have fixed the problem. Back to tweets from NASA astronauts".

The offending spam tweets have now also been removed, although NASA itself is saying nothing as to how the hack was perpetrated in the first place. Most Twitter hacks are related to stolen passwords , which have been appropriated either through the use of rogue third party applications or the use of stupid passwords. One wit suggested that NASA might have been using 10987654321 .

At least it doesn't look like Gary McKinnon was involved , another NASA hacking accusation might ruin any chance he has of avoiding extradition from the UK to the USA.

Dani AI

Generated

As reported and joked, even high-profile institutional accounts can be quickly turned into noisy broadcast channels. The episode underlines a simple operational fact: social accounts should be treated like production systems and covered by an incident playbook, access controls, and routine audits.

Immediate actions for containment and recovery:

  • Temporarily pause scheduled posts and disable publishing from external tools.
  • Reset account credentials through the platform's official flow and rotate any shared passwords.
  • Invalidate active sessions and revoke connected applications; reauthorize only vetted tools.
  • Scan administrative machines for malware and change email/SSO credentials used for account access.
  • Preserve evidence: capture screenshots, export activity/audit logs, and note timestamps for support requests.
  • Notify the platform's support channel and follow its recovery procedures.
  • After control is restored, publish a short factual correction and remove offending content without amplifying it.

Longer-term hardening and governance:

  • Store credentials in a team password manager and ensure each account has a unique password.
  • Enforce two-factor authentication for all admin accounts; prefer hardware security keys or authenticator apps over SMS.
  • Limit direct-login access. Use role-based permissions, centralized publishing tools, and single-sign-on where practical.
  • Maintain an incident playbook, conduct post-incident reviews, run regular permission audits, and include social-media safety in staff training.

The thread from and is a useful cautionary tale: visibility is an asset, but it multiplies risk. Clear ownership, limited access, and practiced recovery steps turn a disruptive hour into a contained, learning event.

CatRambo 1 Junior Poster in Training

It would have been even better if they were selling something like real estate on the Moon. ;)

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

Yeah, don't you just hate hackers/spammers with no sense of humour? :)

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.