In August 2022, Twilio disclosed that attackers had sent text messages to its employees posing as the IT department, harvested their single sign-on credentials on fake login pages, and used them to reach internal tools and customer data. Twilio found 209 of its customers and 93 users of its Authy authentication app were affected. Because Twilio delivers verification codes for many other services, the breach rippled outward: Signal said about 1,900 users' phone numbers were exposed. Twilio was one of more than 130 organisations hit by the same campaign, which Group-IB named 0ktapus. It is a human identity breach, but it shows how identity providers and communications platforms become supply chain targets.
Key takeaways
- Twilio detected unauthorised access on 4 August 2022 after employees received text messages impersonating IT, with links to fake sign-in pages using words such as "Twilio", "Okta" and "SSO".
- Twilio's final count was 209 customers (out of more than 270,000) and 93 Authy users (out of about 75 million) affected. It says there was no evidence that customers' console credentials, authentication tokens or API keys were accessed.
- Downstream, Signal said about 1,900 users' phone numbers were exposed and could have been re-registered to another device.
- Group-IB found the 0ktapus campaign targeted more than 130 organisations and captured 9,931 credentials and 5,441 MFA codes, with phishing kits relaying stolen data to Telegram.
- Twilio responded by moving all employees to FIDO2 security keys, the control that defeats this kind of real-time phishing.
At a glance
| Organisation | Twilio, with downstream impact on customers including Signal |
|---|---|
| When | Related vishing incident on 29 June 2022; access detected on 4 August 2022; last unauthorised activity 9 August 2022 |
| Attacker | The group behind the 0ktapus campaign (also called Scatter Swine) |
| Entry point | SMS phishing of employees leading to fake Okta sign-in pages |
| Identities abused | Employee SSO credentials and one-time MFA codes |
| Impact | 209 customers and 93 Authy users affected; about 1,900 Signal users' phone numbers exposed |
| Category | Human identity (not listed as an NHI or AI agent breach) |
What happened
On 4 August 2022, Twilio detected unauthorised access to information about some customer accounts. Employees had received text messages that appeared to come from Twilio's IT department, with links to a sign-in page. Twilio's incident report says the URLs "used words including 'Twilio,' 'Okta,' and 'SSO' to try and trick users to click on a link taking them to a landing page that impersonated Twilio's sign-in page". Domains included twilio-sso.com, twilio-okta.com and sendgrid-okta.org.
Some employees entered their credentials, and the attackers used them to reach internal systems and customer data. Twilio also linked a smaller incident on 29 June 2022, in which an employee was tricked in a voice phishing call, to the same attackers. The last unauthorised activity it observed was on 9 August.
Twilio's final update put the impact at 209 customers out of more than 270,000, and 93 Authy end users out of about 75 million. It stated there was "no evidence that the malicious actors accessed Twilio customers' console account credentials, authentication tokens, or API keys".
Some customers felt the effect directly. Signal, which uses Twilio for phone number verification, said the attackers could have seen about 1,900 users' phone numbers or SMS verification codes, and could have tried to re-register those numbers to another device. Group-IB later showed Twilio was one of more than 130 organisations targeted by the same campaign, which it named 0ktapus because it went after employees of Okta customers.
Timeline
| Date (2022) | Event |
|---|---|
| 29 June | A Twilio employee is deceived in a voice phishing call; later linked to the same attackers. |
| 4 August | Twilio detects unauthorised access. |
| August | Twilio publishes its incident report, updated in the following weeks. |
| 9 August | Last observed unauthorised activity. |
| 15 August | Signal says about 1,900 users' phone numbers were exposed. |
| 25 August | Group-IB publishes its 0ktapus research: more than 130 organisations targeted. |
| Later updates | Twilio's final count: 209 customers and 93 Authy users affected. |
How it happened: the identity attack path
- Target employees by phone number. The attackers sent text messages directly to employees' phones, outside corporate email filtering.
- Impersonate IT and the identity provider. Messages linked to domains containing the company name and "Okta" or "SSO", hosting convincing copies of the sign-in page.
- Capture passwords and one-time codes in real time. Group-IB found the phishing kit collected usernames and passwords, then one-time MFA codes, and relayed them instantly to the attackers through a Telegram bot, so the codes could be used before they expired.
- Sign in as employees. With valid credentials and codes, the attackers accessed internal tools used to support customers.
- Pivot to downstream targets. Access to customer data, including phone numbers and verification traffic, created opportunities to attack customers' own users, as Signal's case showed.
Impact
- Twilio customers: 209 affected out of more than 270,000.
- Authy users: 93 affected out of about 75 million.
- Signal: about 1,900 users' phone numbers exposed, with a risk of re-registration.
- Wider campaign: 9,931 credentials and 5,441 MFA codes captured across more than 130 organisations, according to Group-IB.
What this means for identity security
Twilio is on our list because it shows how one-time codes can be phished as easily as passwords when the attacker relays them in real time, and how a breach at a communications or identity platform spreads to everyone who relies on it. Twilio's customers trusted it to deliver verification codes. Once attackers could see inside Twilio, that trust became a path to their users.
For non-human identities, the supply chain lesson is the important one. Platforms like Twilio sit in the middle of machine-to-machine flows: applications call their APIs with keys and tokens to send codes and messages. Twilio found no evidence that customers' API keys or tokens were accessed in this case, but a platform breach is exactly the moment to rotate the credentials your systems use with that provider and check how much those credentials can do.
Similar phishing and social engineering tactics against identity systems appear in later incidents on our timeline, such as the MGM Resorts breach.
Recommendations
- Use phishing-resistant MFA. FIDO2 security keys or passkeys bind authentication to the real site, so relayed codes are useless. Twilio moved all employees to FIDO2 keys after this breach. See our Workforce Identity Security Guide.
- Monitor for look-alike domains that contain your company name alongside "sso", "okta" or "login", and take them down quickly.
- Train staff for SMS and voice phishing, not just email, and give them an easy way to report suspicious messages.
- Limit what support tools expose. Internal tools that can see customer data or change authentication settings need least privilege and extra checks.
- Rotate provider credentials after a supplier breach. Review and rotate API keys and tokens your applications use with an affected provider. Our guide to NHI rotation challenges explains how to prepare.
Frequently asked questions
How was Twilio breached in 2022?
Attackers sent text messages to Twilio employees posing as the IT department, with links to fake sign-in pages. Employees who entered their credentials and codes gave the attackers access to internal systems.
How many Twilio customers were affected?
Twilio's final count was 209 customers out of more than 270,000, and 93 Authy users out of about 75 million. Signal separately reported about 1,900 of its users' phone numbers exposed.
What was the 0ktapus campaign?
A phishing campaign, named by Group-IB, that targeted employees of more than 130 organisations using Okta, capturing 9,931 credentials and 5,441 MFA codes. Twilio was one of the victims.
Related NHI Mgmt Group resources
MailChimp breach · Okta breach · Human vs Non-Human Identity · NHI Authentication Guide
How NHI Mgmt Group can help
When a provider you depend on is breached, the credentials your systems use with it become a risk. Our NHI Foundation Level Training Course helps teams inventory, scope and rotate API keys, tokens and service accounts, and respond quickly to supply chain incidents.
References
- Twilio: Incident Report: Employee and Customer Account Compromise (August 2022, with later updates)
- Group-IB: Roasting 0ktapus: The phishing campaign going after Okta identity credentials (25 August 2022)
- TechCrunch: Signal says 1,900 users' phone numbers exposed by Twilio breach (15 August 2022)
- Signal: Twilio Incident: What Signal Users Need to Know