# Kurt Got Got

DevFeed: [Kurt Got Got](<https://devfeed.tech/articles/kurt-got-got-1701.md>)

Original publisher: [Read original article](<https://fly.io/blog/kurt-got-got/>)

Published: 2025-10-08T00:00:00Z

Content type: article

Language: en

Sources: [The Fly Blog](<https://devfeed.tech/sources/the-fly-blog.md>)

Topics: [fly.io](<https://devfeed.tech/topics/fly-io.md>), [X (Twitter)](<https://devfeed.tech/topics/twitter.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>)

Tags: [cdn](<https://devfeed.tech/tags/cdn.md>), [close-to-users](<https://devfeed.tech/tags/close-to-users.md>), [deploy-app-servers](<https://devfeed.tech/tags/deploy-app-servers.md>), [developer](<https://devfeed.tech/tags/developer.md>), [docker](<https://devfeed.tech/tags/docker.md>), [elixir](<https://devfeed.tech/tags/elixir.md>), [fly](<https://devfeed.tech/tags/fly.md>), [fly-io](<https://devfeed.tech/tags/fly-io.md>), [heroku-alternative](<https://devfeed.tech/tags/heroku-alternative.md>), [heroku-competitor](<https://devfeed.tech/tags/heroku-competitor.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [i](<https://devfeed.tech/tags/i.md>), [networking](<https://devfeed.tech/tags/networking.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [postgresql-clusters](<https://devfeed.tech/tags/postgresql-clusters.md>), [servers](<https://devfeed.tech/tags/servers.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

## AI overview

Fly.io describes how its CEO was phished, leading to an account takeover of the company's Twitter/X account. The attack exploited social-engineering cues related to the company's use of developer memes, and the team responded by auditing access to login credentials in 1Password and removing recent access.

## Source excerpt

The $FLY Airdrop is live! Claim your share of the token powering Fly.io's global network of 3M+ apps and (🤮) own a piece of the sky! We know. Our Twitter got owned. We knew within moments of it happening. We know exactly how it happened. Nothing was at risk other than our Twitter account (and one Fly.io employee's self-esteem). Also: for fuck's sake. Here's what happened: Kurt Mackey, our intrepid CEO, got phished. Had this been an impactful attack, we would not be this flippant about it. For this, though, any other tone on our part would be false. How They Got Kurt Two reasons: one, it was a pretty good phishing attack, and two, Twitter fell outside the "things we take seriously" boundary. The phishing attack was effective because it exploited a deep psychological vulnerability in our management team: we are old and out of touch with the youths of today. For many months now, we've had an contractor/intern-type-person Boosting Our Brand on Twitter by posting dank developer memes (I think that's what they're called). The thing about this dankery is that we don't really understand it. I mean, hold on, we know what the memes mean technically. We just don't get why they're funny. However, in pushing back on them, we're up against two powerful forces: The dank memes appear to perform better than the stuff we ourselves write on Twitter. We are reliably informed by our zoomer children that we are too cringe to be trusted on these matters. Here's the phish Kurt got: Diabolical. Like a scalpel expertly wielded against Kurt's deepest middle-aged-dude insecurity. Our ruthless attackers clinically designed this email to trigger an autonomic Kurt response: "oh, what the fuck is this, and why did we post it?" ATO is cool-kid for "got owned" I'm getting a little ahead of the story here. We knew our X.com account had suffered an ATO because a bunch of us simultaneously got another email saying that the @flydotio account's email address now pointed to achilles19969@gmail.com. Our im