Workforce and access social engineering · Also called 0ktapus, Oktapus, employee smishing, SSO smishing, fake password expiry text
Employee SMS phishing (0ktapus-style)
Employee SMS phishing is a campaign of text messages sent to staff, warning that a password has expired or a schedule has changed and linking to a fake company login page. The page passes the employee's password and one-time code to the attacker in real time, who then signs in as the employee.
How it works
- Attackers match employee names to mobile phone numbers and register look-alike domains that combine the company name with words such as sso, okta, or helpdesk.
- Employees receive texts saying their password has expired or their schedule has changed, with a link to log in.
- The fake login page captures the username, password, and one-time code and relays them to the attacker, who signs in before the code expires.
- Some pages also start a download of remote access software, and the attacker uses the stolen access to reach internal systems and customer data.
Red flags
- A text to your phone says your work password has expired or your schedule has changed and asks you to log in.
- The link uses your company's name joined to words like sso, okta, servicedesk, or helpdesk on a domain your company does not use.
- After you enter your password, the page asks for your one-time code.
- The page starts downloading remote access software such as AnyDesk.
If you are targeted
- Stop: do not enter anything more, and close the page.
- If you entered your details, tell your security team at once so they can reset your password and end your sessions; say so even if you are unsure.
- Do not run any file the page downloaded, and let IT check your device.
- Report it to your security team, then to the national service; our Report a scam page lists where, such as ic3.gov in the US.
Prevention
For individuals
- Reach work systems through your bookmarked company portal, never through a link in a text.
- Never type a one-time code into a page you reached from a message.
- Report suspicious texts to your security team, even if you already clicked.
For organisations
- Issue FIDO2 security keys to all staff, because origin binding stops even real-time relay phishing from producing a usable login.
- Block or isolate access to newly registered domains, and block logins from unknown VPNs and residential proxies.
- Build a blame-free reporting culture so employees report a mistake quickly.
Step-by-step controls: the implementation guide
By the numbers
Figures are for the reporting category this scam falls under, not this scam alone.
| Phishing and spoofing losses reported to the FBI IC3 in 2025 | $215.8M | US, 2025, FBI IC3 |
Real cases
2023-08 · US · Disclosed
Retool breached through SMS phishing and a follow-up call, 20232022-08 · US · Disclosed
Twilio employees hit by SMS phishing (0ktapus), 2022
Delivered through: SMS phishing (smishing), Adversary-in-the-middle phishing
How official datasets classify it
- FBI IC3
- Phishing/Spoofing
- MITRE ATT&CK
- T1660, T1566
Questions
- What is 0ktapus-style SMS phishing?
- It describes text message campaigns against employees that link to fake single sign-on pages and relay passwords and one-time codes to the attackers in real time. Twilio and Cloudflare both published accounts of such messages sent to their staff in 2022, and CISA lists Oktapus among the names for the Scattered Spider group.
- Why did hardware security keys stop this attack?
- Security keys are tied to the real website's address, so a look-alike page cannot get a usable login from them. Cloudflare said its keys prevented the attackers from logging in even when employees entered their passwords.
Related scams
- MFA fatigue (push bombing)
- SIM swap
- Help desk password and MFA reset impersonation
- Package delivery text scam