Site navigation

Twilio Hack: Here’s What We Know So Far

Ross Kelly

,

Twilio Hack
A number of Twilio employees were duped in a social engineering attack.

Twilio has revealed a breach of its systems following a sophisticated social engineering attack against employees.

In a statement on Sunday, the firm confirmed that a “limited number” of customers were affected by the hack, and that the firm is working closely with affected clients.

“As the threat actors were able to access a limited number of accounts’ data, we have been notifying the affected customers on an individual basis with the details,” Twilio said.

“If you are not contacted by Twilio, then it means we have no evidence that your account was impacted by this attack.”

What is Twilio?

Twilio is a digital communications platform which allows users to send SMS messages and voice calls, and also provides two-factor authentication services.

The platform is used by more than 250,000 customers, and boasts sizeable clients including Salesforce, VMWare, Uber and Twitter.

Twilio hack – what happened?

In a blog post, Twilio said it first became aware of the incident on 4th August. An initial investigation shows that threat actors sent SMS messages to Twilio employees requesting that they reset passwords.

“Typical text bodies suggested that the employee’s passwords had expired, or that their schedule had changed, and that they needed to log in to a URL the attacker controls,” Twilio explained.

The company described this campaign as a “broad based attack” which succeeded in fooling some employees into providing credentials by logging in via malicious URLs.

These links, which used words including “Twilio”, “Okta” and “SSO” to appear legitimate, directed the user to a landing page that impersonated the Twilio login page.

Thereafter, attackers were able to gain access to employee accounts and access “certain customer data”.

Swift response

After becoming aware of the breach, Twilio said it coordinated with hosting providers serving the malicious URLs to shut those accounts down.

As the text messages originated from US carrier networks, Twilio said it contacted relevant carriers to “shut down the actors” and prevent further attempts to contact staff.

Notably, Twilio said that other companies have informed them they were subject to similar attacks. Cloudflare revealed this week that it had also been targeted in this campaign.

“Based on these factors, we have reason to believe the threat actors are well-organised, sophisticated and methodical in their actions,” the firm said.


Recommended


The Twilio hack is another notable example of the devastating impact that social engineering attacks can have on organisations.

Last year, Robinhood fell victim to a social engineering attack which caused significant disruption for the firm and its user base.

Moving forward, Twilio said it has “reemphasised” security training to ensure that employees are on “high alert” for these specific attack methods. The company is working closely with law enforcement to identify the attackers.

“We have also instituted additional mandatory awareness training on social engineering attacks in recent weeks,” the firm said. “Separately, we are examining additional technical precautions as the investigation progresses.”


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data