Skip to content

2022-08-04 (incident), The date Twilio became aware of the unauthorised access; the smishing messages were sent from mid-July 2022. · US · Twilio

Twilio employees hit by SMS phishing (0ktapus), 2022

Disclosed by the affected organisation.

From mid-July 2022, hundreds of text messages posing as Twilio IT told current and former employees that their passwords had expired or schedules had changed, linking to fake Okta login pages on look-alike domains. Some employees entered their credentials, and the attackers used them to reach internal tools and customer data. Twilio found 209 customers and 93 Authy users affected, and noted researchers had tied the campaign to attacks on many other companies, dubbed 0ktapus.

Timeline

  1. 2022-06-29 In an earlier incident Twilio later linked to the same actors, an employee is tricked by voice phishing into giving credentials.
  2. 2022-08-04 Twilio becomes aware of unauthorised access to a limited number of customer accounts.
  3. 2022-08-07 Twilio publishes its first incident post.
  4. 2022-08-24 Twilio reports that the attackers gained access to 93 Authy users' accounts and registered extra devices.
  5. 2022-10-27 Twilio concludes its investigation: 209 customers and 93 Authy end users were affected.

Lessons

Scam types: Employee SMS phishing (0ktapus-style) · Techniques: SMS phishing (smishing)

Sources

  1. Twilio: Incident Report: Employee and Customer Account Compromise (Company disclosure, primary, accessed 2026-09-24)