/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Twilio discloses “unauthorized access” on August 4 by a “sophisticated” unknown actor using an SMS-based phishing attack on staff to gain info on some accounts

Leaks Private Data via Phishing Jose Montes de Oca / Newslit Daily : 🗞 Axios to Sell to Cox Enterprises for $525MM Pierluigi Paganini / Security Affairs : Twilio discloses data breach that impacted customers and employees Sergiu Gatlan / BleepingComputer : Twilio discloses data breach after SMS phishing attack on employees Jurgita Lapienytė / Cybernews.com : Twilio data breach: phishers fool employees into providing credentials Sheryl Estrada / Fortune : A Twilio exec explains what metric should always accompany customer lifetime value Leigh Mc Gowran / Silicon Republic : What's going on with the Twilio data breach? Phil Muncaster / Infosecurity : Smishing Attack Led to Major Twilio Breach Ryan Naraine / SecurityWeek : Twilio Hacked After Employees Tricked Into Giving Up Login Credentials PYMNTS.com : Digital Authentication Firm Twilio Says Hackers Accessed Customer Data Juha Saarinen / iTnews : Twilio hacked in phishing attack Waqas / HackRead : Hackers Compromise Employee Accounts to Access Twilio Internal Systems Protocol : Amazon's serverless ‘eye-opener’ Cybersecurity Dive : Twilio employees duped by text message phishing attack Emma Roth / The Verge : Twilio suffers data breach after its employees were targeted by a phishing campaign Edward Gately / Channel Futures : Twilio Customers' Data Stolen in Phishing Attacks that Trick Employees Stephen Weigand / SC Media : SMS phishing nabs Twilio employee credentials, allowed access to customer data Tweets: Zack Whittaker / @zackwhittaker : The attackers sent Twilio employees phishing links to trick them into turning over their Okta credentials and app-generated 2FA codes. Twilio said the hackers had “sophisticated abilities to match employee names from sources with their phone numbers.” https://twilio.com/... https://twitter.com/... Rachel Tobac / @racheltobac : Twilio published an incident here that used social engineering on employees to gain access to credentials then internal systems via SMS phishing. Criminals pretexted as IT Support & used SSO likeness w/in domain. Recommend FIDO security keys for this team! https://www.twilio.com/... Paul Walsh / @paul__walsh : Twilio employees were targeted in a predictable phishing attack that lead to their customers being compromised. Twilio has >150,000 customers. This could be worse than the Solar Winds breach as the cybersecurity industry doesn't have a category for SMS. https://www.linkedin.com/... https://twitter.com/... Irene Kaggwa Sewankambo / @ucc_ed : The common weakest link in cyber security is the human factor. Phone calls, SMS, whatapps & emails are being used by criminals to circumvent security safeguards. Teach your employees, family, friends & neighbours to verify origin/source of messages first https://www.twilio.com/... Tonya Riley / @tonyajoriley : Twilio + a number of researchers are saying the phishing attack against the company is related to a larger campaign. If you're a researcher looking at this would love to chat! @cz_binance : Web2 companies security affects Web3. Be very careful of phishing attacks on SMS now. https://www.twilio.com/... Sean Metcalf / @pyrotek3 : If you haven't yet moved off of SMS/text for MFA, this is the risk. At Trimarc, we see most Azure AD customers with MFA configured have SMS as an option. Disable SMS as a 2nd factor when possible. Authenticator App is best for most scenarios. FIDO2 is the strongest method. https://twitter.com/... Dave Kennedy / @hackingdave : Twilio data breach has a good amount of detail on how the phishing campaign was successful. Tactics are consistent with what we are seeing with adversaries using SMS/texts in pretexts more and more. Phish domains were specific to Twilio and Okta. https://www.twilio.com/... Justin Elze / @hackinglz : This SMS approach has been working in the red team space for several years now with great success. There also isn't an easy fix other than a more resistant form of MFA. https://twitter.com/... Zack Whittaker / @zackwhittaker : Twilio said it had “heard from other companies that they, too, were subject to similar attacks.” TechCrunch has learned the same hackers also targeted a U.S. internet giant and several international IT companies — though what impact, if any, isn't known. https://techcrunch.com/... Rachel Tobac / @racheltobac : Here's an example of the SMS-based phish received by employees at Twilio, We see the pretext come in via text, pretext as IT Support informing of SSO login creds “expiring” and to reset pw via targeted SSO impersonating phish link. Use FIDO security key MFA to prevent ATO. https://twitter.com/... Zack Whittaker / @zackwhittaker : New: Phone and messaging giant Twilio says some customer data was accessed after hackers phished employee passwords. TechCrunch has learned it's part of a wider phishing campaign targeting U.S. internet and international IT companies. https://techcrunch.com/... See also Mediagazer

TechCrunch Carly Page

Discussion

  • @zackwhittaker Zack Whittaker on x
    The attackers sent Twilio employees phishing links to trick them into turning over their Okta credentials and app-generated 2FA codes. Twilio said the hackers had “sophisticated abilities to match employee names from sources with their phone numbers.” https://twilio.com/... https…
  • @racheltobac Rachel Tobac on x
    Twilio published an incident here that used social engineering on employees to gain access to credentials then internal systems via SMS phishing. Criminals pretexted as IT Support & used SSO likeness w/in domain. Recommend FIDO security keys for this team! https://www.twilio.com/…
  • @paul__walsh Paul Walsh on x
    Twilio employees were targeted in a predictable phishing attack that lead to their customers being compromised. Twilio has >150,000 customers. This could be worse than the Solar Winds breach as the cybersecurity industry doesn't have a category for SMS. https://www.linkedin.com/.…
  • @ucc_ed Irene Kaggwa Sewankambo on x
    The common weakest link in cyber security is the human factor. Phone calls, SMS, whatapps & emails are being used by criminals to circumvent security safeguards. Teach your employees, family, friends & neighbours to verify origin/source of messages first https://www.twilio.com/..…
  • @tonyajoriley Tonya Riley on x
    Twilio + a number of researchers are saying the phishing attack against the company is related to a larger campaign. If you're a researcher looking at this would love to chat!
  • @cz_binance @cz_binance on x
    Web2 companies security affects Web3. Be very careful of phishing attacks on SMS now. https://www.twilio.com/...
  • @pyrotek3 Sean Metcalf on x
    If you haven't yet moved off of SMS/text for MFA, this is the risk. At Trimarc, we see most Azure AD customers with MFA configured have SMS as an option. Disable SMS as a 2nd factor when possible. Authenticator App is best for most scenarios. FIDO2 is the strongest method. https:…
  • @hackingdave Dave Kennedy on x
    Twilio data breach has a good amount of detail on how the phishing campaign was successful. Tactics are consistent with what we are seeing with adversaries using SMS/texts in pretexts more and more. Phish domains were specific to Twilio and Okta. https://www.twilio.com/...
  • @hackinglz Justin Elze on x
    This SMS approach has been working in the red team space for several years now with great success. There also isn't an easy fix other than a more resistant form of MFA. https://twitter.com/...
  • @zackwhittaker Zack Whittaker on x
    Twilio said it had “heard from other companies that they, too, were subject to similar attacks.” TechCrunch has learned the same hackers also targeted a U.S. internet giant and several international IT companies — though what impact, if any, isn't known. https://techcrunch.com/..…
  • @racheltobac Rachel Tobac on x
    Here's an example of the SMS-based phish received by employees at Twilio, We see the pretext come in via text, pretext as IT Support informing of SSO login creds “expiring” and to reset pw via targeted SSO impersonating phish link. Use FIDO security key MFA to prevent ATO. https:…
  • @zackwhittaker Zack Whittaker on x
    New: Phone and messaging giant Twilio says some customer data was accessed after hackers phished employee passwords. TechCrunch has learned it's part of a wider phishing campaign targeting U.S. internet and international IT companies. https://techcrunch.com/...
  • @mikko @mikko on x
    A new Twilio blog post that starts with «the security of our customers' data is of paramount importance» means bad news. https://www.twilio.com/...