/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Group-IB details hacking group 0ktapus, responsible for the recent breaches of Twilio and 130+ organizations that netted close to 10K employees' credentials

Carly Page / TechCrunch :

TechCrunch Carly Page

Context & Ripple Effects

Twilio initially described the August 4 intrusion as a sophisticated SMS-phishing attack against employees. Group-IB’s attribution ties that event to a broader 0ktapus campaign spanning more than 130 organizations and nearly 10,000 employee credentials.

The incident’s scope later included compromised Authy user accounts, showing that the employee-targeted breach had consequences beyond Twilio’s internal systems.

First-order effects

  • Twilio and the other organizations attributed to 0ktapus must treat employee credentials gathered through the campaign as exposed and assess which systems and customer-facing accounts were reachable with them.
  • Group-IB’s identification of 0ktapus gives affected organizations a common actor and attack pattern to investigate, rather than handling the Twilio intrusion as an isolated event.

Second-order effects

  • Twilio’s disclosure that the intrusion began with SMS phishing of its staff puts greater pressure on organizations using employee-held credentials to review how phishing-resistant their access controls are.
  • The later Authy account compromise raises the operational stakes for Twilio’s authentication services, because attackers’ access extended from staff credentials to login-code generation for affected users.

Third-order effects

  • The episode points to identity-focused campaigns becoming a cross-company risk: one phishing playbook can create simultaneous remediation work across infrastructure providers and their customers.
  • If similar campaigns continue to target employee access and authentication tools together, security response will increasingly center on limiting credential reuse and reducing the value of a single successful phishing event.

The trend: Cybercrime campaigns are concentrating on employee identity access, using phishing to turn one repeatable tactic into breaches across many organizations.

Discussion

  • @neurovagrant Ian Campbell on x
    Really good data herein relating to a bunch of the okta-targeted activity I've been crowing about for months. https://twitter.com/...
  • @ajvicens AJ Vicens on x
    New look at some technical details, scope and information related to someone possibly involved in the Twilio breach from @GroupIB_GIB https://blog.group-ib.com/0ktapus
  • @campuscodi Catalin Cimpanu on x
    Group-IB report on 0ktapus, a phishing campaign targeting Okta accounts -started in March 2022 -collected creds sent to a Telegram channel -collected almost 10k credentials -from more than 130 orgs https://blog.group-ib.com/0ktapus https://twitter.com/...
  • @groupib_gib @groupib_gib on x
    The Group-IB team found that the threat actor managed to steal 9,931 user credentials, including 3,129 records with emails, and 5,441 records with #MFA codes: https://blog.group-ib.com/0ktapus #phishing #0ktapus https://twitter.com/...
  • @jcybersec_ @jcybersec_ on x
    Group IB analysis of the Okta phishing kits we have been seeing recently🔍 ⚠️This was the group which caused the Twilio breach and caused the Signal alert a week ago https://blog.group-ib.com/0ktapus