Don't click on that Twilio message - it could be a scam

Phishing
(Image credit: Vektor Illustration/Shutterstock)

If you get an “urgent” message from Twilio, be extra careful, as it’s most likely a scam aiming to trick you into giving away sensitive data, or hard-earned money. 

This warning was sent out by the company itself, confirming it suffered a recent data breach with attackers using the stolen data to attack its customers.

Twilioy says it doesn’t know just yet who the perpetrators are, but it did describe them as “well-organized, sophisticated and methodical in their actions”. Whoever it was, they first tricked a couple of Twilio employees into giving away their login credentials. Then, they used that information to sneak into the company network, map out the endpoints, and steal even more data. 

Usual phishing topics

Once enough data was collected, the attackers then used it against Twilio users and employees. The company said that recently, both current and former employees started getting text messages, seemingly from the company’s IT department. The threat actors are able to match employee names from sources with their phone numbers, which Twilio describes as a “sophisticated” move. 

These messages are all the usual phishing topics, from expired passwords, to changed schedules, and anything else that might trick the user into clicking the provided URL right away. 

Furthermore, the URLs used words including "Twilio," "Okta," and "SSO" to try and trick people into believing the link was legitimate. 

The texts came from U.S. carrier networks, Twilio further said. Jointly, they managed to shut the bad actors down, after which the company reached out to the hosting providers serving the malicious URLs, and had those terminated, as well. Twilio is not the only victim here, too. Other companies, it was said, were subject to similar attacks, prompting all victims to join forces.

“Despite this response, the threat actors have continued to rotate through carriers and hosting providers to resume their attacks,” the company concluded.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
Close up of a business person using a smartphone.
Watch out, malicious PDF files are being used again in phishing attacks
Hook on Keyboard
Fake DocuSign and HubSpot phishing emails target 20,000 Microsoft Azure accounts
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before