In August of 2022, a text message arrived on the phones of employees at a company most people have never dealt with directly. It looked routine. Your password has expired, it said. Tap here to reset it. Some of them tapped. The page that opened looked exactly like the sign-in screen they used every day, so they did what it asked. They entered their password, and then they entered the login code that was supposed to keep that password safe.
The company was Twilio, and the text was not aimed at Twilio alone. The message used the company’s name and sounded like the help desk. The link pointed to a web address that stitched the company’s name together with words like Okta, SSO or help, the kind of address you would half expect the real IT department to use. Sending fake texts like this in bulk to a company’s staff has a name: smishing, phishing by text message. The page behind the link was a copy of the real Okta sign-in screen the company actually used.
The interesting part is what happened after the password. The moment an employee submitted it, a second page asked for their login code, the one-time code that is supposed to save you when a password is stolen. In the few seconds while the employee read it off their phone and typed it in, the attacker typed it straight into the real Twilio login. The fake page was a middleman, passing the code through to the real door before it went stale. Researchers call this a real-time phishing relay. The narration reaches for a con artist standing at the real entrance with a phone to their ear: you read your code out to what you think is your own company, they read it straight through to the real lock, and they are inside before the code expires.
A stronger password would not have helped. The strength of a password only matters when someone has to guess it or crack it, and nobody here had to. The employee handed it over, onto a page built to catch it, and it was used within seconds. The same is true of the code. The one idea to hold on to for the rest of this story is that a code you can read and type is a code that can be relayed. Which leaves a question hanging: these employees had a second factor and it still failed, so what kind of second factor does not fail this way? That question has an answer, and it arrives at the end.
To see why the break-in reached so far, you have to know what Twilio is. Twilio is infrastructure. It is the plumbing other companies’ apps use to send text messages and phone-number verification codes. When an app texts you a six-digit code to confirm it is really you, there is a good chance Twilio is quietly sending that text on the app’s behalf. So Twilio’s customers are other companies, and those companies have their own users, millions of them. When the attacker logged into Twilio’s internal systems with that stolen session, the data within reach was not really Twilio’s own. It was data about Twilio’s customers, and by extension the people those customers serve. Signal, Okta and a long list of other businesses sat downstream of a single break-in. Think of the courier that carries the verification mail for hundreds of different companies. You do not break into each company one at a time. You break into the courier. That is what a supply-chain compromise is: you attack something your target depends on.
One thing is easy to get wrong here. When you hear that Signal users were affected, the natural assumption is that Signal was hacked, or careless. Neither is true. Signal itself was not breached at all. A service Signal relied on was, and the trust between them carried the damage downstream.
Twilio’s own count of affected customers did not hold still. When it first became aware of the intrusion in early August it described a limited number of customer accounts. A week or so later it put a figure on it: a hundred and twenty-five. By late August that was a hundred and sixty-three. When Twilio published its final report that October, the count had reached two hundred and nine, out of a customer base of more than two hundred and seventy thousand. That climb is not a sign of evasiveness. It is what an honest investigation looks like from the outside: you find the floor first, and the real number surfaces as you dig. There was also Authy, Twilio’s own two-factor app, used by around seventy-five million people. For ninety-three of those users the attacker managed to register an extra device onto the account, which could let someone catch future codes. A breach touching a service that large tends to be reported as though everyone was affected. Here, it was ninety-three accounts.
The final report revealed one more piece, reaching back before the August texts. At the end of June, weeks earlier, the same crew had already got to a Twilio employee by a different route: a phone call. Someone rang an employee and talked their way into their credentials, the spoken version of the same con, sometimes called vishing. With those credentials they reached contact information for a limited number of customers before Twilio caught it and shut it down within about twelve hours.
Signal is where the breach became real for ordinary people. Signal used Twilio for one specific job: sending the SMS codes that verify your phone number when you set up the app. For roughly nineteen hundred Signal users, one of two things became possible. Either their phone number was exposed as being registered to Signal, or the verification code sent to them was exposed, and with that code an attacker could have tried to re-register the number onto a device of their own. That is a real harm. The risk was account access tied to a phone number. The messages themselves were never exposed. Signal was specific about it: the attacker did not gain access to anyone’s message history, contact lists, profile information, or the list of people they had blocked. What leaked was the doorway, the phone number and its verification code. It was never the messages behind the door.
Twilio was one target among many. When Group-IB, a security firm, mapped the whole campaign, the scale was the part that stood out. Twilio was one of more than a hundred and thirty organizations hit by the same operation using the same kit. Group-IB counted a hundred and sixty-nine look-alike domains built for it, and across every target the crew harvested close to ten thousand sets of login credentials and more than five thousand of the one-time codes. One repeatable phishing kit, pointed at company after company, run at volume. You do not have to be brilliant a hundred and thirty times over. You have to be adequate once and then industrial about repeating it.
Group-IB named the campaign 0ktapus, with a zero in place of the O, because so many of the fake pages imitated Okta, the sign-in service a lot of these companies used. Okta, tracking the same crew, called them Scatter Swine, and Okta ended up on both sides of this: its login page was the disguise the attacker wore, and Okta was also one of Twilio’s downstream customers whose data was reachable in the breach. You may have heard this crew called Scattered Spider. That name came later, first used at the end of 2022, and through 2023 researchers and government agencies gathered a lot of related activity under it. The advisories that carry the Scattered Spider name list the older names, 0ktapus and Scatter Swine, among its aliases, but they do not name Twilio. So the honest way to describe the people behind the 2022 breach is the plain one: a financially motivated criminal group, in it for money, running a phishing operation at industrial scale.
Now go back about two weeks, to the twentieth of July, 2022, before Twilio’s breach became public. The same campaign, the same style of text, hit Cloudflare, a large internet-infrastructure firm. It landed the same way it did everywhere else. At least seventy-six Cloudflare employees got the phishing text, all within less than a minute of each other. Three of them clicked through and entered their credentials on the fake page, the same mistake made at Twilio and across the whole campaign. The human layer broke at Cloudflare too. And still, none of those logins succeeded.
Here is why a key holds where a code does not. Cloudflare does not use one-time codes. Every employee is issued a physical security key, a small device that plugs in or taps against the phone, built to a standard called FIDO2. The attacker had valid usernames and valid passwords and still could not get past that key. A one-time code is just characters, and anything you can read, you can be tricked into typing somewhere else. That is the relay. A security key hands over no characters at all. It runs a private calculation directly with the website, and it is locked to that site’s real web address. On the genuine address the key works normally. It will not answer a look-alike phishing address at all, so there is nothing to read and nothing to relay. A key cut for exactly one lock: hold it up to a lock with the wrong address stamped on it and it will not turn. This is what security people mean by phishing-resistant.
There is a tempting conclusion to reach here, and it is the wrong one. You might decide the fix is better training, or smarter employees who do not fall for texts. Cloudflare’s own numbers close that door. Three of their people did fall for it. The training did not stop the attack, but the key did. What stood between a stolen password and a real break-in was the kind of second factor those employees happened to be using.
**Sources & further reading:**
- Twilio, Incident Report: Employee and Customer Account Compromise (August 7, 2022; updated August 10, August 24 and October 27, 2022)
- Cloudflare, The mechanics of a sophisticated phishing scam and how we stopped it (August 9, 2022)
- Signal, Twilio Incident: What Signal Users Need to Know (August 2022)
- Group-IB, Roasting 0ktapus: The Phishing Kit Behind Twilio and Cloudflare Attacks (August 25, 2022)
- Okta Security, Detecting Scatter Swine: Threat Actor Leverages Okta Brand to Build Convincing Phishing Infrastructure (August 25, 2022)
- CISA and FBI, joint advisory AA23-320A, #StopRansomware: Scattered Spider (November 16, 2023)
