Twilio reveals it was hit by another data breach

Red padlock open on electric circuits network dark red background
(Image credit: Shutterstock/Chor muang)

The data breach that hit Twilio in August 2022 resulting in the theft of customer information data, was not the first time the same threat actor targeted the company, it has confirmed.

Following weeks of research, Twilio says it has now wrapped up its investigation into the incident, and in a follow-up blog post, unveiled that the same malicious actor also managed to compromise its systems in late June 2022.

However unlike the August incident that was enabled with a smishing attack, the June one was done through vishing - voice phishing. 

Customer data stolen

“In the June incident, a Twilio employee was socially engineered through voice phishing (or “vishing”) to provide their credentials, and the malicious actor was able to access customer contact information for a limited number of customers,” the company explained. It further stated that it eliminated the hacker within 12 hours, and by July 2, notified everyone who was affected by the incident. 

In the August attack, Twilio said, the attackers used login credentials obtained through the smishing attack to breach internal non-production systems and endpoints. There, they found the data of 209 customers, as well as 93 Authy end users. 

"209 customers – out of a total customer base of over 270,000 – and 93 Authy end users – out of approximately 75 million total users – had accounts that were impacted by the incident," Twilio said. The investigation has also shown that customers’ console account credentials, API keys, or authentication tokens were most likely not accessed. 

The company disclosed the incident on August 7, but later learned that the hackers lingered around for two more days. "The last observed unauthorized activity in our environment was on August 9, 2022," the company added.

According to the report, the Twilio attack was not an isolated incident, but rather part of a larger cybercrime campaign conducted by a group known as Scatter Swine (AKA 0ktapus). At least 130 organizations were hit, including MailChimp and Cloudflare. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
China
Salt Typhoon hackers used this clever technique to attack US networks
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
Salt Typhoon attacks may have hit more US firms than previously thought
Avast cybersecurity
Zapier tells customers their data may have been accessed
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Major breach hits employee screening firm - 3.3 million affected as hackers steal DISA data
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
China
Salt Typhoon strikes again - more US ISPs, universities and telecoms networks hit by Chinese hackers
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)