Cloudflare says some employees fell for an SMS phishing scam, but the company's hardware MFA keys stopped the hackers from accessing its internal network
Unusually resourced threat actor has targeted multiple companies in recent days. — At least two security-sensitive companies … Source: The Cloudflare Blog .
Ars Technica Dan Goodin
Related Coverage
- The mechanics of a sophisticated phishing scam and how we stopped it The Cloudflare Blog · Matthew Prince
- Cloudflare says it was almost fooled by a phishing attack TechRadar · Sead Fadilpašić
- Hackers Behind Twilio Breach Also Targeted Cloudflare Employees The Hacker News · Ravie Lakshmanan
- Cloudflare employees also hit by hackers behind Twilio breach BleepingComputer · Sergiu Gatlan
- Cloudflare targeted by a sophisticated phishing attack Cybernews.com · Jurgita Lapienytė
- Cloudflare thwarts ‘sophisticated’ phishing attack strategy that bruised Twilio Cybersecurity Dive
- Customer Engagement Platform Twilio Suffers Breach GovTech · Jule Pattison-Gordon
Discussion
-
@eastdakota
Matthew Prince
on x
Phishing attacks are getting more targeted and sophisticated. Here's an in-depth walk through of how one we recently saw worked and how we were able to stop it using Cloudflare One tools. https://blog.cloudflare.com/ ... #zerotrust
-
@3141592f
Jason Craig
on x
. @Cloudflare gets it. Nice work @shellcromancer et al. “...Cloudflare does not use TOTP codes. Instead, every employee at the company is issued a FIDO2-compliant security key from a vendor like YubiKey” https://blog.cloudflare.com/ ...
-
@adspedia
Val Vesa
on x
Around the same time as Twilio was attacked, we saw an attack with very similar characteristics also targeting Cloudflare's employees. We were able to thwart the attack through our own use of Cloudflare One products. https://blog.cloudflare.com/ ... #ZeroTrust
-
@cloudflare
@cloudflare
on x
Yesterday, August 8, 2022, Twilio shared that they'd been compromised by a targeted phishing attack. Around the same time as Twilio was attacked, we saw an attack with very similar characteristics also targeting Cloudflare's employees. https://blog.cloudflare.com/ ...
-
@notbind
@notbind
on x
“Having a paranoid but blame-free culture is critical for security,” https://arstechnica.com/...
-
@racheltobac
Rachel Tobac
on x
Thankfully, Cloudflare uses FIDO security keys & was able to thwart mid attack. Also cool to see they analyzed & documented stages of this method. This provides context for this attack method (even if it happened differently at Twilio), as many had questions on TOTP harvesting.
-
@racheltobac
Rachel Tobac
on x
*Update on SMS Phish Methods* Cloudflare saw similar attack as Twilio, stages: 1.SMS phish 2.Cred harvest page (Okta, etc) 3.Creds relayed fast to attacker via Telegram 4.TOTP harvest page 5.TOTP relay to attacker 6.Anydesk payload (remote access tool) https://blog.cloudflare.com…