Skip to main content

Donald Trump Is Using a Private Gmail Account to Secure the Most Powerful Twitter Account in the World

All that's stopping an outsider from seizing control of @POTUS is someone's personal Gmail password.

The new American president’s Twitter account isn’t a means of communication as much as it is a tool for confusion, propaganda, and unceasing assault. But Donald Trump has shown his tweets can move the stock market, provoke foreign powers, and dominate news cycles, so the account’s potential to shake the world is unprecedented. And all that’s stopping an outsider from seizing control of @POTUS could be someone’s personal Gmail password.

Screen-Shot-2017-01-26-at-11.35.45-AM-1485450271
Image: Screenshot from Twitter

If you forget your Twitter password, the company allows you to easily reset the code through a link sent to an email address you designate in your account settings. This same process makes it elementary to hijack that Twitter account if you have access to the email account in question: Just request a password reset, wait for the link to arrive, and lock your victim out of their own Twitter account.  If two-factor authentication is enabled, it would impede but not necessarily stop a motivated or sophisticated attacker.

Trump’s account is an obviously juicy target for such an attack, representing what BuzzFeed’s Joe Bernstein described as “a national security disaster waiting to happen.” An unauthorized declaration of, say, imminent hostilities or economic sanctions coming from the president’s official account could destabilize the entire world.

According to hacker and Twitter user @WauchulaGhost, Trump’s account is  set to email password reset requests to a personal Gmail account (it appears to be that of Dan Scavino, his social media chief), and it reveals the first two letters of the account (enough to surmise it’s probably Scavino’s). This signals to hackers that all they need to do to illicitly broadcast to the president’s 14 million online followers is get into said Gmail account, which may or may not be secured with some form of two-factor authentication. Even with such an extra layer of authentication, knowing the private email address of a senior White House employee would make them a target for spearphishing attacks like those that befell the DNC and John Podesta last summer.

According to a CNN report, WauchulaGhost “says he found the likely email associated with Melania Trump’s handle within twenty minutes, and “the email associated with Vice President Mike Pence was easy to guess once you saw the redacted version: vi***************@gmail.com, which WauchulaGhost pieced together as vicepresident2017@gmail.com.”

It appears that in the days since WauchulaGhost first tweeted about the vulnerability, the option to reset the @POTUS password via text message or what appears to be an @DonaldJTrump.com address have been removed. Bizarrely, the Gmail option remains active as of today for both Trump and Press Secretary Sean Spicer:

The irony given Trump’s campaign assaults on Hillary Clinton’s use of a private email service is of course obvious.

Update: Jan. 26, 2017

An earlier version of this story did not address the possibility that two-factor authentication could impede unauthorized access to Trump’s Twitter account.

Update 2: Jan. 26, 2017

As of 1:02 PM today, the email required to reset Trump’s Twitter account was changed to what appears to be a White House address.

 

IT’S EVEN WORSE THAN WE THOUGHT.

What we’re seeing right now from Donald Trump is a full-on authoritarian takeover of the U.S. government. 

This is not hyperbole.

Court orders are being ignored. MAGA loyalists have been put in charge of the military and federal law enforcement agencies. The Department of Government Efficiency has stripped Congress of its power of the purse. News outlets that challenge Trump have been banished or put under investigation.

Yet far too many are still covering Trump’s assault on democracy like politics as usual, with flattering headlines describing Trump as “unconventional,” “testing the boundaries,” and “aggressively flexing power.” 

The Intercept has long covered authoritarian governments, billionaire oligarchs, and backsliding democracies around the world. We understand the challenge we face in Trump and the vital importance of press freedom in defending democracy.

We’re independent of corporate interests. Will you help us?

Donate

IT’S BEEN A DEVASTATING year for journalism — the worst in modern U.S. history.

We have a president with utter contempt for truth aggressively using the government’s full powers to dismantle the free press. Corporate news outlets have cowered, becoming accessories in Trump’s project to create a post-truth America. Right-wing billionaires have pounced, buying up media organizations and rebuilding the information environment to their liking.

In this most perilous moment for democracy, The Intercept is fighting back. But to do so effectively, we need to grow.

That’s where you come in. Will you help us expand our reporting capacity in time to hit the ground running in 2026?

We’re independent of corporate interests. Will you help us?

Donate

I’M BEN MUESSIG, The Intercept’s editor-in-chief. It’s been a devastating year for journalism — the worst in modern U.S. history.

We have a president with utter contempt for truth aggressively using the government’s full powers to dismantle the free press. Corporate news outlets have cowered, becoming accessories in Trump’s project to create a post-truth America. Right-wing billionaires have pounced, buying up media organizations and rebuilding the information environment to their liking.

In this most perilous moment for democracy, The Intercept is fighting back. But to do so effectively, we need to grow.

That’s where you come in. Will you help us expand our reporting capacity in time to hit the ground running in 2026?

We’re independent of corporate interests. Will you help us?

Donate

Latest Stories

Join The Conversation