The 15-year-old hacker known as Cosmo the God was behind the takeover of a Westboro Baptist Church member’s Twitter feed, a source with direct knowledge of the attack confirmed to Wired on Monday.
Cosmo gained access to the @DearShirley Twitter account via an e-mail account, and from there was able to leverage control of the Twitter feed itself, according to the source, who spoke on condition of anonymity. As of this writing, the account remains up and operating, and seemingly beyond the control of its owner.
Westboro Baptist Church is notorious for picketing funerals of American soldiers killed in action in Iraq and Afghanistan. Last week the organization apparently announced its intention to protest at the funerals of the children killed at Sandy Hook, with spokewoman Shirley Lynn Phelps-Roper tweeting the following: “Westboro will picket Sandy Hook Elementary School to sing praise to God for the glory of his work in executing his judgment.”
The sentiment was echoed on Westboro Baptist Church’s website, which included the line “God sent the shooter to Newton, CT.”
The announcement triggered astonished outrage from observers, and the hacker group Anonymous declared open season on the group, publishing contact information for many of its members, including Phelps-Roper. Phelps-Roper’s Twitter account @DearShirley was then taken over early Monday morning.
Cosmo the God has been able to keep control of the account using a flaw in Twitter’s Zendesk system that allows an attacker to close an account support ticket before it’s acted on, according to the source, who demonstrated inside knowledge of the account takeover.
Cosmo and his group UG Nazi took part in many of the highest-profile hacking incidents of 2012, including taking down websites for NASDAQ, CIA.gov, and UFC.com, redirecting 4Chan’s DNS to point to its own Twitter feed, and defeating CloudFlare CEO Matthew Prince’s Google two-step authentication.
The teen’s social-engineering techniques allowed him to gain access to user accounts at Amazon, PayPal and a slew of other companies. He was arrested in June, as part of a multi-state FBI sting and was recently sentenced to probation until his 21st birthday, during which time he is prohibited from using the internet without supervision and prior consent.
The latest hack would seem to violate those terms. But it’s garnered Cosmo an unending stream of Twitter praise. “I love that @cosmothegod hacked @DearShirley!! I’m glad that there is one less hateful twitter account,” wrote one fan. “I think @cosmothegod deserves a medal for hacking @DearShirley and making everyone’s day,” another tweeted.
Wired sought to reach Westboro Baptist Church for comment, but its phone line was consistently busy.