Twilio discloses “unauthorized access” on August 4 by a “sophisticated” unknown actor using an SMS-based phishing attack on staff to gain info on some accounts
Leaks Private Data via Phishing Jose Montes de Oca / Newslit Daily : 🗞 Axios to Sell to Cox Enterprises for $525MM Pierluigi Paganini / Security Affairs : Twilio discloses data breach that impacted customers and employees Sergiu Gatlan / BleepingComputer : Twilio discloses data breach after SMS phishing attack on employees Jurgita Lapienytė / Cybernews.com : Twilio data breach: phishers fool employees into providing credentials Sheryl Estrada / Fortune : A Twilio exec explains what metric should always accompany customer lifetime value Leigh Mc Gowran / Silicon Republic : What's going on with the Twilio data breach? Phil Muncaster / Infosecurity : Smishing Attack Led to Major Twilio Breach Ryan Naraine / SecurityWeek : Twilio Hacked After Employees Tricked Into Giving Up Login Credentials PYMNTS.com : Digital Authentication Firm Twilio Says Hackers Accessed Customer Data Juha Saarinen / iTnews : Twilio hacked in phishing attack Waqas / HackRead : Hackers Compromise Employee Accounts to Access Twilio Internal Systems Protocol : Amazon's serverless ‘eye-opener’ Cybersecurity Dive : Twilio employees duped by text message phishing attack Emma Roth / The Verge : Twilio suffers data breach after its employees were targeted by a phishing campaign Edward Gately / Channel Futures : Twilio Customers' Data Stolen in Phishing Attacks that Trick Employees Stephen Weigand / SC Media : SMS phishing nabs Twilio employee credentials, allowed access to customer data Tweets: Zack Whittaker / @zackwhittaker : The attackers sent Twilio employees phishing links to trick them into turning over their Okta credentials and app-generated 2FA codes. Twilio said the hackers had “sophisticated abilities to match employee names from sources with their phone numbers.” https://twilio.com/... https://twitter.com/... Rachel Tobac / @racheltobac : Twilio published an incident here that used social engineering on employees to gain access to credentials then internal systems via SMS phishing. Criminals pretexted as IT Support & used SSO likeness w/in domain. Recommend FIDO security keys for this team! https://www.twilio.com/... Paul Walsh / @paul__walsh : Twilio employees were targeted in a predictable phishing attack that lead to their customers being compromised. Twilio has >150,000 customers. This could be worse than the Solar Winds breach as the cybersecurity industry doesn't have a category for SMS. https://www.linkedin.com/... https://twitter.com/... Irene Kaggwa Sewankambo / @ucc_ed : The common weakest link in cyber security is the human factor. Phone calls, SMS, whatapps & emails are being used by criminals to circumvent security safeguards. Teach your employees, family, friends & neighbours to verify origin/source of messages first https://www.twilio.com/... Tonya Riley / @tonyajoriley : Twilio + a number of researchers are saying the phishing attack against the company is related to a larger campaign. If you're a researcher looking at this would love to chat! @cz_binance : Web2 companies security affects Web3. Be very careful of phishing attacks on SMS now. https://www.twilio.com/... Sean Metcalf / @pyrotek3 : If you haven't yet moved off of SMS/text for MFA, this is the risk. At Trimarc, we see most Azure AD customers with MFA configured have SMS as an option. Disable SMS as a 2nd factor when possible. Authenticator App is best for most scenarios. FIDO2 is the strongest method. https://twitter.com/... Dave Kennedy / @hackingdave : Twilio data breach has a good amount of detail on how the phishing campaign was successful. Tactics are consistent with what we are seeing with adversaries using SMS/texts in pretexts more and more. Phish domains were specific to Twilio and Okta. https://www.twilio.com/... Justin Elze / @hackinglz : This SMS approach has been working in the red team space for several years now with great success. There also isn't an easy fix other than a more resistant form of MFA. https://twitter.com/... Zack Whittaker / @zackwhittaker : Twilio said it had “heard from other companies that they, too, were subject to similar attacks.” TechCrunch has learned the same hackers also targeted a U.S. internet giant and several international IT companies — though what impact, if any, isn't known. https://techcrunch.com/... Rachel Tobac / @racheltobac : Here's an example of the SMS-based phish received by employees at Twilio, We see the pretext come in via text, pretext as IT Support informing of SSO login creds “expiring” and to reset pw via targeted SSO impersonating phish link. Use FIDO security key MFA to prevent ATO. https://twitter.com/... Zack Whittaker / @zackwhittaker : New: Phone and messaging giant Twilio says some customer data was accessed after hackers phished employee passwords. TechCrunch has learned it's part of a wider phishing campaign targeting U.S. internet and international IT companies. https://techcrunch.com/... See also Mediagazer