Skip to content

Workforce and access social engineering · Also called 0ktapus, Oktapus, employee smishing, SSO smishing, fake password expiry text

Employee SMS phishing (0ktapus-style)

Employee SMS phishing is a campaign of text messages sent to staff, warning that a password has expired or a schedule has changed and linking to a fake company login page. The page passes the employee's password and one-time code to the attacker in real time, who then signs in as the employee.

How it works

  1. Attackers match employee names to mobile phone numbers and register look-alike domains that combine the company name with words such as sso, okta, or helpdesk.
  2. Employees receive texts saying their password has expired or their schedule has changed, with a link to log in.
  3. The fake login page captures the username, password, and one-time code and relays them to the attacker, who signs in before the code expires.
  4. Some pages also start a download of remote access software, and the attacker uses the stolen access to reach internal systems and customer data.

Red flags

If you are targeted

Where to report, by country

Prevention

For individuals

For organisations

Step-by-step controls: the implementation guide

By the numbers

Figures are for the reporting category this scam falls under, not this scam alone.

Phishing and spoofing losses reported to the FBI IC3 in 2025$215.8MUS, 2025, FBI IC3

Real cases

Delivered through: SMS phishing (smishing), Adversary-in-the-middle phishing

How official datasets classify it

FBI IC3
Phishing/Spoofing
MITRE ATT&CK
T1660, T1566

Questions

What is 0ktapus-style SMS phishing?
It describes text message campaigns against employees that link to fake single sign-on pages and relay passwords and one-time codes to the attackers in real time. Twilio and Cloudflare both published accounts of such messages sent to their staff in 2022, and CISA lists Oktapus among the names for the Scattered Spider group.
Why did hardware security keys stop this attack?
Security keys are tied to the real website's address, so a look-alike page cannot get a usable login from them. Cloudflare said its keys prevented the attackers from logging in even when employees entered their passwords.

Related scams

Read more