Twilio Confirms Data Breach After Sophisticated SMS Phishing Attack

Hackers access data of 125 Twilio customers by tricking employees with convincing text messages. The sophisticated threat actors continue to evade shutdown efforts by rapidly rotating their infrastructure.

Communications giant Twilio confirms that hackers access customer data after tricking employees into handing over their corporate login credentials. The company discovers the unauthorized access to customer account information on August 4 and later verifies that malicious actors compromise the data of 125 customers. Twilio collects sensitive details like addresses, payment information, IP addresses, and proof of identity, though the exact data exposed in this incident remains unconfirmed.

The attack relies on a sophisticated SMS phishing campaign where threat actors send text messages pretending to be from Twilio’s IT department. These fraudulent messages claim that an employee's password expires or that their schedule changes, directing targets to log in through a malicious spoofed web address. The attackers make the messages look highly legitimate by including corporate terminology like "Okta" and "SSO" to successfully bypass employee skepticism.

Twilio collaborates with U.S. carriers, registrars, and hosting providers to shut down the malicious URLs and block the deceptive text messages. However, the threat actors prove to be highly methodical and continue their attacks by quickly rotating through different carriers and hosting services. Reports indicate that these same hackers also set up phishing pages impersonating several other organizations, including a U.S. internet company and an IT outsourcing firm.

Read More at the original source →