Twilio suffers data breach after its employees were targeted by a phishing campaign

Digital communication platform Twilio was hacked after a phishing campaign tricked its employees into revealing their login credentials (via TechCrunch). The company disclosed the data breach in a post on its blog, noting that only “a limited number” of customer accounts were affected by the attack. Twilio allows web services to send SMS messages and place voice calls over telephone networks and is used by companies including Uber, Twitter, and Airbnb.

The hack occurred on August 4th and involved a bad actor sending SMS messages to Twilio employees that asked them to reset their password or alerted them to a change in their schedule. Each message included a link with keywords, like “Twilio,” “SSO” (single sign-on), and “Okta,” the name of the user authentication service used by many companies. The link directed employees to a page that mimicked a real Twilio sign-in page, allowing hackers to collect the information employees inputted there.

After it became aware of the breach, Twilio worked with US phone carriers to shut down the SMS scheme and also had web hosting platforms take down the phony sign-in pages. Despite this, Twilio says that hackers managed to swap to new hosting providers and mobile carriers to continue their campaign.

“Based on these factors, we have reason to believe the threat actors are well-organized, sophisticated and methodical in their action,” Twilio adds. “Socially engineered attacks are — by their very nature — complex, advanced, and built to challenge even the most advanced defenses.”

Twilio’s working with law enforcement to find out who’s responsible for the campaign and says it also heard from companies that “were subject to similar attacks.” Twilio has since shut down access to the compromised employee accounts and will also alert any customers affected by the breach.

Social engineering is becoming an increasingly common tactic for hackers. Earlier this year, a report from Bloomberg revealed that both Apple and Meta shared data with hackers pretending to be law enforcement officials. Last year, a hacker tricked a Robinhood customer service representative into disclosing the information of over 7 million customers.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
How startups are trying to address SA’s healthcare access gap thumbnail

How startups are trying to address SA’s healthcare access gap

Healthcare startups in South Africa are playing their part in helping to address the inequality in the country’s healthcare sector. As the world’s most unequal country, South Africa’s lopsided wealth distribution has created a two-tiered healthcare system whose inequality mirrors that of apartheid, a system supposedly replaced by democracy 29 years ago. On the one
Read More
OnePlus has rolled out the September security patch to these phones thumbnail

OnePlus has rolled out the September security patch to these phones

Security updates are designed to keep Android devices as secure as possible, but you’re only as safe as your latest update. OnePlus does promise regular updates for its smartphones for at least two years, so let’s see how they’re handling the September 2021 security update. OnePlus September 2021 security update — What’s new? Google released…
Read More
Tesla 4680 vai ter os condutores sentados nas baterias thumbnail

Tesla 4680 vai ter os condutores sentados nas baterias

A Tesla anunciou que irá utilizar a sua nova tecnologia de baterias 4680 em todos os seus carros. Esta é uma grande mudança para a empresa, e também para os consumidores. A nova bateria é muito maior do que a antiga, o que significa que há mais capacidade de armazenamento e maior alcance. A Tesla…
Read More
Dutch Amazon is listing the 12900K, 12700K, and 12600K thumbnail

Dutch Amazon is listing the 12900K, 12700K, and 12600K

In a nutshell: Dutch Amazon has become the latest retailer to list part of the Alder Lake series ahead of their launch. Although the listing doesn’t purport to be selling the CPUs, unlike some questionable Chinese listings, it confirms prior information about packaging and includes new pricing information. By now, you’re probably familiar with Alder…
Read More
Η Google εφευρίσκει ξανά το ιστορικό του Google Chrome με τα Chrome Journeys – Δείτε screenshot thumbnail

Η Google εφευρίσκει ξανά το ιστορικό του Google Chrome με τα Chrome Journeys – Δείτε screenshot

H Η Google ανακοίνωσε σημαντικές νέες λειτουργίες που έρχονται στον γνωστό σε όλους μας Google Chrome, μία από τις οποίες θα αλλάξει ριζικά τον τρόπο με τον οποίο επιστρέφουμε στους ιστότοπους που έχουμε ερευνήσει στο παρελθόν. Ο λόγος για τα Journeys, μια νέα λειτουργία η οποία θα παίρνει τις ιστοσελίδες του ιστορικού αναζήτησης και θα…
Read More
Index Of News
Total
0
Share