Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Twilio Breach 2022: How SMS Phishing of Employees…
Breach analysis Incident: 4 Aug 2022

Twilio Breach 2022: How SMS Phishing of Employees Opened a Supply Chain Path to Signal and 130 Other Organisations

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 7 min read
On this page

In August 2022, Twilio disclosed that attackers had sent text messages to its employees posing as the IT department, harvested their single sign-on credentials on fake login pages, and used them to reach internal tools and customer data. Twilio found 209 of its customers and 93 users of its Authy authentication app were affected. Because Twilio delivers verification codes for many other services, the breach rippled outward: Signal said about 1,900 users' phone numbers were exposed. Twilio was one of more than 130 organisations hit by the same campaign, which Group-IB named 0ktapus. It is a human identity breach, but it shows how identity providers and communications platforms become supply chain targets.

Key takeaways

  • Twilio detected unauthorised access on 4 August 2022 after employees received text messages impersonating IT, with links to fake sign-in pages using words such as "Twilio", "Okta" and "SSO".
  • Twilio's final count was 209 customers (out of more than 270,000) and 93 Authy users (out of about 75 million) affected. It says there was no evidence that customers' console credentials, authentication tokens or API keys were accessed.
  • Downstream, Signal said about 1,900 users' phone numbers were exposed and could have been re-registered to another device.
  • Group-IB found the 0ktapus campaign targeted more than 130 organisations and captured 9,931 credentials and 5,441 MFA codes, with phishing kits relaying stolen data to Telegram.
  • Twilio responded by moving all employees to FIDO2 security keys, the control that defeats this kind of real-time phishing.

At a glance

OrganisationTwilio, with downstream impact on customers including Signal
WhenRelated vishing incident on 29 June 2022; access detected on 4 August 2022; last unauthorised activity 9 August 2022
AttackerThe group behind the 0ktapus campaign (also called Scatter Swine)
Entry pointSMS phishing of employees leading to fake Okta sign-in pages
Identities abusedEmployee SSO credentials and one-time MFA codes
Impact209 customers and 93 Authy users affected; about 1,900 Signal users' phone numbers exposed
CategoryHuman identity (not listed as an NHI or AI agent breach)

What happened

On 4 August 2022, Twilio detected unauthorised access to information about some customer accounts. Employees had received text messages that appeared to come from Twilio's IT department, with links to a sign-in page. Twilio's incident report says the URLs "used words including 'Twilio,' 'Okta,' and 'SSO' to try and trick users to click on a link taking them to a landing page that impersonated Twilio's sign-in page". Domains included twilio-sso.com, twilio-okta.com and sendgrid-okta.org.

Some employees entered their credentials, and the attackers used them to reach internal systems and customer data. Twilio also linked a smaller incident on 29 June 2022, in which an employee was tricked in a voice phishing call, to the same attackers. The last unauthorised activity it observed was on 9 August.

Twilio's final update put the impact at 209 customers out of more than 270,000, and 93 Authy end users out of about 75 million. It stated there was "no evidence that the malicious actors accessed Twilio customers' console account credentials, authentication tokens, or API keys".

Some customers felt the effect directly. Signal, which uses Twilio for phone number verification, said the attackers could have seen about 1,900 users' phone numbers or SMS verification codes, and could have tried to re-register those numbers to another device. Group-IB later showed Twilio was one of more than 130 organisations targeted by the same campaign, which it named 0ktapus because it went after employees of Okta customers.

Timeline

Date (2022)Event
29 JuneA Twilio employee is deceived in a voice phishing call; later linked to the same attackers.
4 AugustTwilio detects unauthorised access.
AugustTwilio publishes its incident report, updated in the following weeks.
9 AugustLast observed unauthorised activity.
15 AugustSignal says about 1,900 users' phone numbers were exposed.
25 AugustGroup-IB publishes its 0ktapus research: more than 130 organisations targeted.
Later updatesTwilio's final count: 209 customers and 93 Authy users affected.

How it happened: the identity attack path

  1. Target employees by phone number. The attackers sent text messages directly to employees' phones, outside corporate email filtering.
  2. Impersonate IT and the identity provider. Messages linked to domains containing the company name and "Okta" or "SSO", hosting convincing copies of the sign-in page.
  3. Capture passwords and one-time codes in real time. Group-IB found the phishing kit collected usernames and passwords, then one-time MFA codes, and relayed them instantly to the attackers through a Telegram bot, so the codes could be used before they expired.
  4. Sign in as employees. With valid credentials and codes, the attackers accessed internal tools used to support customers.
  5. Pivot to downstream targets. Access to customer data, including phone numbers and verification traffic, created opportunities to attack customers' own users, as Signal's case showed.

Impact

  • Twilio customers: 209 affected out of more than 270,000.
  • Authy users: 93 affected out of about 75 million.
  • Signal: about 1,900 users' phone numbers exposed, with a risk of re-registration.
  • Wider campaign: 9,931 credentials and 5,441 MFA codes captured across more than 130 organisations, according to Group-IB.

What this means for identity security

Twilio is on our list because it shows how one-time codes can be phished as easily as passwords when the attacker relays them in real time, and how a breach at a communications or identity platform spreads to everyone who relies on it. Twilio's customers trusted it to deliver verification codes. Once attackers could see inside Twilio, that trust became a path to their users.

For non-human identities, the supply chain lesson is the important one. Platforms like Twilio sit in the middle of machine-to-machine flows: applications call their APIs with keys and tokens to send codes and messages. Twilio found no evidence that customers' API keys or tokens were accessed in this case, but a platform breach is exactly the moment to rotate the credentials your systems use with that provider and check how much those credentials can do.

Similar phishing and social engineering tactics against identity systems appear in later incidents on our timeline, such as the MGM Resorts breach.

Recommendations

  • Use phishing-resistant MFA. FIDO2 security keys or passkeys bind authentication to the real site, so relayed codes are useless. Twilio moved all employees to FIDO2 keys after this breach. See our Workforce Identity Security Guide.
  • Monitor for look-alike domains that contain your company name alongside "sso", "okta" or "login", and take them down quickly.
  • Train staff for SMS and voice phishing, not just email, and give them an easy way to report suspicious messages.
  • Limit what support tools expose. Internal tools that can see customer data or change authentication settings need least privilege and extra checks.
  • Rotate provider credentials after a supplier breach. Review and rotate API keys and tokens your applications use with an affected provider. Our guide to NHI rotation challenges explains how to prepare.

Frequently asked questions

How was Twilio breached in 2022?

Attackers sent text messages to Twilio employees posing as the IT department, with links to fake sign-in pages. Employees who entered their credentials and codes gave the attackers access to internal systems.

How many Twilio customers were affected?

Twilio's final count was 209 customers out of more than 270,000, and 93 Authy users out of about 75 million. Signal separately reported about 1,900 of its users' phone numbers exposed.

What was the 0ktapus campaign?

A phishing campaign, named by Group-IB, that targeted employees of more than 130 organisations using Okta, capturing 9,931 credentials and 5,441 MFA codes. Twilio was one of the victims.

MailChimp breach · Okta breach · Human vs Non-Human Identity · NHI Authentication Guide

How NHI Mgmt Group can help

When a provider you depend on is breached, the credentials your systems use with it become a risk. Our NHI Foundation Level Training Course helps teams inventory, scope and rotate API keys, tokens and service accounts, and respond quickly to supply chain incidents.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org