Twilio Confirms Hackers Stole Customer Data Through Elaborate SMS Phishing
Hackers breach Twilio by tricking employees into handing over corporate login credentials via sophisticated SMS phishing messages. The attack compromises the data of 125 customers, including major tech firms.
Communications giant Twilio confirms that hackers access customer data after successfully tricking employees into handing over their corporate login credentials. The company discovers this unauthorized access to customer account information on August 4 and later confirms that malicious actors compromise the data of 125 customers. While Twilio does not yet specify exactly what information is stolen, the company's privacy policy indicates it collects customer addresses, payment details, IP addresses, and occasionally proof of identity.
The attack relies on a sophisticated SMS phishing campaign where threat actors send text messages pretending to be from Twilio's IT department. These fraudulent messages claim that an employee's password has expired or that their schedule has changed, directing the targets to log in through a spoofed web address controlled by the hackers. The threat actors make these messages look highly legitimate by including corporate security terms like "Okta" and "SSO" to bypass the employees' suspicions.
Twilio works with U.S. carriers and hosting providers to shut down the malicious URLs, but the attackers remain undeterred and continuously rotate to new providers to resume their campaigns. The company describes the threat actors as well-organized, sophisticated, and methodical in their actions. Reports also reveal that the same hacking group sets up similar phishing pages impersonating other organizations, including a U.S. internet company and an IT outsourcing firm.