Data Breaches

Twilio discloses data breach after SMS phishing attack

0

Digital communication platform Twilio discloses a data breach after threat actors have stolen employee credentials obtained through a sophisticated SMS phishing attack.

Twilio is an American firm that provides programmable communication tools for making and receiving phone calls, sending and receiving text messages, and performing other communication functions using its web service APIs.

The company has more than 5,000 employees in 17 countries, and its revenues in 2021 are US$2.84 billion.

The communication giant became aware of unauthorized access to information on August 4th. The attack against the employee base succeeded in fooling some employees into providing their credentials. The attackers then used the stolen credentials to gain access to some of the internal systems, where they were able to access certain customer data.

The company did not disclose the number of affected employees and customers.

The company employees received phishing messages impersonating the IT department, the content of the messages informed the recipient that their passwords had expired, or that their schedule had changed, and urged them to log in to a URL the attacker controls. The URLs in the messages included words like “Twilio,” “Okta,” and “SSO” in order to trick users into clicking on a link redirecting them to a landing page that impersonated Twilio’s sign-in page.

The text messages originated from U.S. carrier networks. The company has collaborated with carriers to stop the malicious messages, as well as their registrars and hosting providers to shut down the malicious URLs. The company has also revoked access to the compromised employee accounts.

As the threat actors were able to access a limited number of accounts’ data, the affected customers were notified. The company informed that the Twilio Security Incident Response Team will post additional updates if there are any changes.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

North Korean hackers lure crypto experts with fake job offers

Previous article

Cisco hacked by Yanluowang ransomware gang

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *