Attackers Hijacked Segment Founder's X Account
A phishing campaign exploited X's OAuth system to gain unauthorized access to high-profile accounts.
Updated on Sept. 29, 2026 in Cybersecurity

Live Poll
Do you trust that third-party applications requesting access to your social media accounts are safe?
Attackers compromised Segment co-founder Peter Reinhardt's X account by using a phishing campaign that impersonated a journalist. The incident was part of a broader infrastructure dubbed Asteria, which used fake booking pages to trick users into granting account permissions.
Why it matters
This incident highlights how attackers are shifting from standard credential theft to exploiting OAuth permissions for deeper, more persistent account access. By abusing trusted services like Calendly, threat actors are increasingly bypassing traditional security filters.
The attack bypassed password requirements by prompting targets to authorize a malicious application named CalendarBookings. This OAuth-based access allowed the attackers to read and write posts and access private messages directly.
The players
Peter Reinhardt
Co-founder of Segment, a customer data platform that tracks user interactions across web and mobile applications.
Anthony Gibbs
A security researcher focused on identifying and reporting phishing infrastructure.
The details
Attackers initiated the exploit by sending targets to a deceptive booking page styled after a major publication to establish false legitimacy. They then utilized a genuine Calendly booking flow as a redirect to the malicious site. Once at the phishing destination, the attackers requested that the target grant the CalendarBookings application extensive permissions within X's OAuth authorization system, which acts as a bridge for third-party apps to interact with a user's account.
Timeline
December 2025: A campaign impersonating 75 brands was identified.
September 9-11, 2026: Researcher Anthony Gibbs traced five phishing sites to the Asteria backend.
September 17, 2026: Abuse reports were filed with domain registrars and platforms.
The Tech Race
This event confirms the increasing prevalence of permission-based attacks over traditional password-stealing methods. It illustrates a growing reliance on platform-specific authorization systems by threat actors looking to subvert standard authentication layers.
Users should exercise extreme caution when granting third-party applications access to their social media accounts via OAuth prompts. Even if a link appears to originate from a legitimate service like Calendly, unexpected permission requests should be treated as suspicious.
The takeaway
This attack underscores that your account's security depends as much on the third-party apps you authorize as it does on your password. Monitor your linked application settings on social platforms to revoke access for any tools you do not actively use or recognize.
Further reading
For more on the current threat landscape, explore our coverage of Cybersecurity.
Source note: This article includes information reported by Cybernews.
Live Poll
Do you trust that third-party applications requesting access to your social media accounts are safe?









