A look at 2022's worst breaches, leaks, ransomware attacks, state-sponsored hacking campaigns, and digital takeovers, including at least two Twilio breaches
Context & Ripple Effects
Wired's year-end security retrospective is a recurring franchise — its look back at 2020's worst hacks covered SolarWinds and Twitter — and the 2022 edition lands on at least two Twilio breaches as defining incidents of the year. The anchor case is the August intrusion disclosed in Twilio's own disclosure, where a 'sophisticated' unknown actor used SMS-based phishing against multiple staff to reach customer account data.
The irony is structural: Twilio sits inside other companies' communications and authentication stacks, so a breach there propagates beyond its own perimeter. The retrospective also arrives just ahead of threat-intel data like CrowdStrike's 2024 Global Threat Report, which later quantified how far cloud intrusions and data-theft extortion climbed after the period this piece surveys.
First-order effects
- Twilio faces renewed scrutiny of its internal security posture, with the SMS-phishing entry vector — aimed at employees rather than infrastructure — now on the public record twice in one year.
- Organizations whose account information was exposed through Twilio inherit downstream risk from a vendor they may not have treated as a direct attack surface.
Second-order effects
- Vendors selling authentication and communications services get pulled into a trust debate: buyers who route verification traffic or 2FA through providers like Twilio must weigh supplier compromise as a first-class threat.
- Security vendors gain a sales argument for phishing-resistant employee authentication, since the year's marquee breaches succeeded by texting staff, not by breaking encryption or code.
Third-order effects
- Read alongside the 2020 retrospective's supply-chain lesson (SolarWinds), the pattern points toward attackers consistently targeting the human and vendor layers — meaning enterprise security budgets shift toward identity and third-party risk rather than perimeter defense.
- If annual retrospectives keep surfaging repeat victims like Twilio, boards and regulators face growing pressure to treat recurring breaches at critical infrastructure providers as a systemic failure, not isolated incidents.
The trend: Major breaches are migrating from exploited software flaws to phished people and trusted vendors, making identity-centric attacks the defining security story across successive years.