Toutes les vulnérabilités
HIGHOpSec

OPSEC-TWILIO-2022

Communications · Twilio

Résumé

On August 7, 2022, Twilio disclosed that attackers breached internal systems via an SMS phishing (smishing) campaign against employees. Staff received texts impersonating Twilio IT, claiming password expiry or schedule changes and using terms like Okta and SSO, directing them to fake login pages that harvested credentials. Several employees entered credentials, giving access to internal tools and data for 125 customers. Downstream, roughly 1,900 Signal users had phone numbers or SMS verification codes exposed and at least one account was re-registered to an attacker device, though message content and contacts remained protected. The broader 0ktapus campaign hit around 130 organizations.

Références

Vulnérabilités liées

Tout OpSec →