2022-08-04 (incident), The date Twilio became aware of the unauthorised access; the smishing messages were sent from mid-July 2022. · US · Twilio
Twilio employees hit by SMS phishing (0ktapus), 2022
Disclosed by the affected organisation.
From mid-July 2022, hundreds of text messages posing as Twilio IT told current and former employees that their passwords had expired or schedules had changed, linking to fake Okta login pages on look-alike domains. Some employees entered their credentials, and the attackers used them to reach internal tools and customer data. Twilio found 209 customers and 93 Authy users affected, and noted researchers had tied the campaign to attacks on many other companies, dubbed 0ktapus.
Timeline
- 2022-06-29 In an earlier incident Twilio later linked to the same actors, an employee is tricked by voice phishing into giving credentials.
- 2022-08-04 Twilio becomes aware of unauthorised access to a limited number of customer accounts.
- 2022-08-07 Twilio publishes its first incident post.
- 2022-08-24 Twilio reports that the attackers gained access to 93 Authy users' accounts and registered extra devices.
- 2022-10-27 Twilio concludes its investigation: 209 customers and 93 Authy end users were affected.
Lessons
- Use phishing-resistant MFA such as security keys, which a fake login page cannot relay.
- Monitor and take down look-alike domains that pair your company name with words such as sso or okta.
- Tell staff and former staff that IT will not text them links to reset passwords.
Scam types: Employee SMS phishing (0ktapus-style) · Techniques: SMS phishing (smishing)
Sources
- Twilio: Incident Report: Employee and Customer Account Compromise (Company disclosure, primary, accessed 2026-09-24)