Cloudflare says some employees fell for an SMS phishing scam, but the company's hardware MFA keys stopped the hackers from accessing its internal network
Unusually resourced threat actor has targeted multiple companies in recent days. — At least two security-sensitive companies … Source: The Cloudflare Blog .
Context & Ripple Effects
Cloudflare's disclosure lands two days after [[a:981649|Twilio's admission that the same kind of SMS-phishing campaign reached some of its staff accounts]], and the company describes the attacker as unusually well-resourced and active against multiple security-sensitive firms. The difference in outcome is the story: where Twilio saw unauthorized access, Cloudflare's hardware MFA keys held the line even though employees fell for the phish.
The episode also echoes a longer arc — [[a:980753|Microsoft's finding that a phishing campaign hit 10K+ organizations by hijacking Office 365 authentication even on MFA-protected accounts]] showed that any MFA can be attacked; Cloudflare's result shows the defense is not whether you use MFA but which kind.
First-order effects
- Cloudflare employees who entered credentials into the phishing pages were exposed, but the hardware keys blocked the follow-through, leaving the internal network uncompromised while the same-style attack produced actual account access at Twilio.
Second-order effects
- Security teams at companies targeted by this actor now face a concrete procurement argument for replacing SMS-based 2FA with phishing-resistant hardware keys, since the corpus shows SMS codes being phished as far back as the Iran-linked campaign that bypassed SMS 2FA on Gmail and Yahoo Mail.
Third-order effects
- If well-resourced actors keep treating MFA itself as the attack surface — from SMS interception to MFA bombing of Apple users — the industry splits into tiers where SMS-based 2FA becomes table-stakes theater and hardware-backed, phishing-resistant authentication becomes the baseline for security-sensitive firms.
The trend: Authentication is migrating from what-you-receive (SMS codes) to what-you-hold (hardware keys) as attackers shift from stealing passwords to defeating the second factor itself.