Twilio Breach 2022: SMS Phishing and the Limits of MFA
Updated: Aug 31
A text message impersonating IT, a spoofed login page, and one entered code were enough to hand attackers real-time access to Twilio's internal systems. MFA adds an important layer of protection, but some forms of MFA can still be defeated when attackers capture credentials and authentication codes in real time.
Case type: Social engineering / SMS phishing (smishing)
Identified: Aug 4, 2022 Disclosed: Aug 8, 2022
Attribution: 0ktapus campaign
When organizations think about phishing, they often picture suspicious emails with misspelled words and questionable links. Modern attackers, however, increasingly target employees through other channels, including text messages.
In August 2022, communications platform Twilio experienced a breach that began not with a software vulnerability, but with a carefully crafted SMS phishing campaign targeting employees. The campaign succeeded by combining social engineering with an authentication flow that could still be defeated when employees entered credentials and MFA codes into an attacker-controlled page.
Twilio first became aware of unauthorized access on August 4, 2022, and disclosed the incident publicly within days. According to the company's own account, attackers sent text messages to employees that appeared to come from Twilio's IT department. The messages created a sense of urgency, often suggesting a password had expired or a work schedule had changed, and directed employees to what appeared to be a legitimate login page.
In reality, the website was controlled by the attackers. Twilio later confirmed the malicious URLs used words like "Twilio," "Okta," and "SSO" to make the spoofed page feel credible. Several employees entered their credentials and multi-factor authentication (MFA) information into the fraudulent site. The attackers then used those credentials to gain access to internal systems and customer-related information. On August 10, Twilio updated its disclosure with an initial scope: approximately 125 customers had data accessed, all of them notified. The final count, confirmed in Twilio's October incident report, reached 209 customers and 93 users of its Authy two-factor authentication app.
The attack was highly targeted. Rather than sending generic phishing messages to thousands of people, the attackers focused specifically on employees and tailored the messages to appear credible and relevant.
The picture got bigger two months later. In its October 2022 final report, Twilio revealed that the same attacker was likely responsible for a separate, brief incident on June 29, 2022, in which a different employee was socially engineered through a voice-phishing (vishing) call into handing over credentials, giving the attacker access to a limited number of customer accounts. Twilio said that earlier incident had been detected and shut down within about 12 hours, but the connection between the two attacks wasn't made public until months after the August breach had already been disclosed.
Attackers do not need to defeat every technical control
Attackers do not need to defeat every technical control directly if they can manipulate the authentication process around it. Organizations spend significant resources securing networks, deploying endpoint protection, implementing MFA, and monitoring systems. Those controls are essential, and none of them can fully prevent an employee from voluntarily providing credentials to a convincing attacker.
The attackers used social engineering to turn legitimate authentication processes into a path for unauthorized access.
The phish moved to a channel nobody trained for
Security awareness programs have traditionally focused on email-based phishing attacks. However, attackers increasingly use alternative communication channels, including:
Many employees are conditioned to be cautious with email but may lower their guard when receiving text messages. Because texts often feel more personal and immediate, attackers can use them to create urgency and pressure quick decision-making. Organizations that only train employees to recognize email phishing may leave significant gaps in their defenses.
A code handed over willingly works in real time
One of the most important lessons from the Twilio incident is that multi-factor authentication is not immune to social engineering. MFA remains one of the most effective security controls available and should absolutely be implemented wherever possible. However, organizations sometimes develop a false sense of confidence after deploying it.
If an employee willingly enters their credentials and authentication code into a phishing site, attackers can often use that information in real time. Technology reduces risk, but its effectiveness also depends on how authentication processes, employee decisions, and organizational controls interact.
Not one decision. A set of conditions.
The question organizations should ask isn't "why did employees enter their codes?" A more useful question is: what conditions made that decision possible? In this case, the conditions were built into the channel itself.
Slowing down has to be normal, not brave
A strong security culture encourages employees to slow down, question unusual requests, and verify communications before taking action. Employees should feel comfortable asking questions such as:
Organizations with mature security cultures also make it easy for employees to report suspicious activity without fear of embarrassment or punishment. Often, the first employee who reports a phishing attempt can prevent dozens of others from falling victim to the same campaign.
"The Easiest Path Exploits Trust."
The Twilio breach got past technically sound defenses by leveraging trust, urgency, and routine behavior. The attackers did not need to exploit a software vulnerability to gain the initial access described in Twilio’s incident reporting. They found a path through trusted access and the human decisions surrounding it.
As organizations continue investing in technical controls, they should also evaluate how effectively they are measuring and managing human risk. Security awareness, phishing resistance, and reporting culture are not soft skills. They are security controls.
BECAUSE ATTACKERS LOOK FOR THE EASIEST PATH TO TRUSTED ACCESS. STRONG SECURITY MAKES THAT PATH HARDER AT EVERY LAYER.
Sources
Twilio, "Incident Report: Employee and Customer Account Compromise," 2022: https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack
Group-IB, "Roasting 0ktapus: The phishing campaign going after Okta identity credentials," August 25, 2022: https://www.group-ib.com/blog/0ktapus/
BleepingComputer, "Twilio discloses data breach after SMS phishing attack on employees," August 8, 2022: https://www.bleepingcomputer.com/news/security/twilio-discloses-data-breach-after-sms-phishing-attack-on-employees/
The Hacker News, "Twilio Reveals Another Breach from the Same Hackers Behind the August Hack," October 29, 2022: https://thehackernews.com/2022/10/twilio-reveals-another-breach-from-same.html


Comments