Attackers Break Into Twilio Customer Data Via Phishing Attack

Share post:

Cloud communications company Twilio has confirmed a data breach in which attackers stole customer data via a text message phishing attack.

According to the company, the attackers gained access to its systems after tricking and stealing the credentials of several employees.

To carry out the attack, the threat actors impersonated Twilio’s IT department and asked them to click on URLs with “Twillo,” “Okta,” and “SSO” keywords. Twilio’s employees were tricked into clicking on the embedded links after being warned that their passwords had expired and needed to be changed.

“The text messages originated from U.S. carrier networks. We worked with the U.S. carriers to shut down the actors and worked with the hosting providers serving the malicious URLs to shut those accounts down,” Twilio said.

While the attackers are yet to be identified, the company said the problem has been reported to law enforcement and investigations are ongoing.

Twilio has revoked the employee accounts compromised during the attack in order to block the attackers from accessing its systems.

“As the threat actors were able to access a limited number of accounts’ data, we have been notifying the affected customers on an individual basis with the details,” Twilio said.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways