Twilio customer data exposed after its staffers got phished
(2022/08/08)
- Reference: 1659980705
- News link: https://www.theregister.co.uk/2022/08/08/twilio_phishing_attack/
- Source link:
Twilio confirmed a breach of the communication giant's network and accessed "a limited number" of customer accounts after tricking some employees into falling for a phishing attack.
The company declined to respond to The Register 's inquiries about how many customers' accounts were compromised and the type of data that the crooks stole, but the investigation is ongoing.
Twilio said it first became aware of the breach on August 4, after current and former employees received text messages claiming to be from Twilio's IT department saying the employees' passwords were expired, or for some other reason they needed to log into a phony URL that looked like Twilio's sign-in page.
[1]
In reality, however, the webpages were attacker-controlled sites, and once the employees entered their usernames and passwords, the crooks grabbed the credentials and used those to access Twilio's internal systems.
[2]
[3]
All of the text messages originated from US-carrier networks, and Twilio said it worked with the network operators and hosting providers to shut down the malicious accounts. "Additionally, the threat actors seemed to have sophisticated abilities to match employee names from sources with their phone numbers," the cloud communication biz noted.
"We continue to notify and are working directly with customers who were affected by this incident," the company wrote in an [4]incident report , adding that if you don't hear from Twilio, that means the biz believes your data is safe.
[5]
Twilio provides messaging, call center and two-factor authentication services, among others, to about [6]256,000 customers including Lyft, American Red Cross, Salesforce, Twitter and VMware. But this incident wasn't alone, Twilio said, but part of a larger campaign.
[7]Slack leaked hashed passwords from its servers for years
[8]Ex-T-Mobile US store owner phished staff, raked in $25m from unlocking phones
[9]Nomad to crypto thieves: Please give us back 90%, keep 10% as a reward. Deal?
[10]Hi, I'll be your ransomware negotiator today – but don't tell the crooks that
We're told that that breach was part of a larger, coordinated attack against several companies — not just Twilio. The firms reportedly coordinated their response and collaborated with carriers to stop the phishing texts and hosting providers to shut down the phone URLs.
"Despite this response, the threat actors have continued to rotate through carriers and hosting providers to resume their attacks," according to the incident report. "Based on these factors, we have reason to believe the threat actors are well-organized, sophisticated and methodical in their actions.
Twilio declined to identify other victim organizations or provide additional information about who is believed to be behind the attacks. The services provider is working with law enforcement and a "leading forensics firm" as it continues to investigate the breach.
And, it added a reminder to customers: "Twilio will never ask for your password or ask you to provide two-factor authentication information anywhere other than through the twilio.com portal." ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.twilio.com/blog/august-2022-social-engineering-attack
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.twilio.com/press/releases/twilio-announces-fourth-quarter-and-full-year-2021-results
[7] https://www.theregister.com/2022/08/08/slack_passwords/
[8] https://www.theregister.com/2022/08/03/tmobile_unlock_prison_phone/
[9] https://www.theregister.com/2022/08/05/nomad_white_hat_payback/
[10] https://www.theregister.com/2022/08/06/interview_ransomware_negotiator/
[11] https://whitepapers.theregister.com/
The company declined to respond to The Register 's inquiries about how many customers' accounts were compromised and the type of data that the crooks stole, but the investigation is ongoing.
Twilio said it first became aware of the breach on August 4, after current and former employees received text messages claiming to be from Twilio's IT department saying the employees' passwords were expired, or for some other reason they needed to log into a phony URL that looked like Twilio's sign-in page.
[1]
In reality, however, the webpages were attacker-controlled sites, and once the employees entered their usernames and passwords, the crooks grabbed the credentials and used those to access Twilio's internal systems.
[2]
[3]
All of the text messages originated from US-carrier networks, and Twilio said it worked with the network operators and hosting providers to shut down the malicious accounts. "Additionally, the threat actors seemed to have sophisticated abilities to match employee names from sources with their phone numbers," the cloud communication biz noted.
"We continue to notify and are working directly with customers who were affected by this incident," the company wrote in an [4]incident report , adding that if you don't hear from Twilio, that means the biz believes your data is safe.
[5]
Twilio provides messaging, call center and two-factor authentication services, among others, to about [6]256,000 customers including Lyft, American Red Cross, Salesforce, Twitter and VMware. But this incident wasn't alone, Twilio said, but part of a larger campaign.
[7]Slack leaked hashed passwords from its servers for years
[8]Ex-T-Mobile US store owner phished staff, raked in $25m from unlocking phones
[9]Nomad to crypto thieves: Please give us back 90%, keep 10% as a reward. Deal?
[10]Hi, I'll be your ransomware negotiator today – but don't tell the crooks that
We're told that that breach was part of a larger, coordinated attack against several companies — not just Twilio. The firms reportedly coordinated their response and collaborated with carriers to stop the phishing texts and hosting providers to shut down the phone URLs.
"Despite this response, the threat actors have continued to rotate through carriers and hosting providers to resume their attacks," according to the incident report. "Based on these factors, we have reason to believe the threat actors are well-organized, sophisticated and methodical in their actions.
Twilio declined to identify other victim organizations or provide additional information about who is believed to be behind the attacks. The services provider is working with law enforcement and a "leading forensics firm" as it continues to investigate the breach.
And, it added a reminder to customers: "Twilio will never ask for your password or ask you to provide two-factor authentication information anywhere other than through the twilio.com portal." ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.twilio.com/blog/august-2022-social-engineering-attack
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YvGHh1zD-6dkP@N84Dc@cwAAAEc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.twilio.com/press/releases/twilio-announces-fourth-quarter-and-full-year-2021-results
[7] https://www.theregister.com/2022/08/08/slack_passwords/
[8] https://www.theregister.com/2022/08/03/tmobile_unlock_prison_phone/
[9] https://www.theregister.com/2022/08/05/nomad_white_hat_payback/
[10] https://www.theregister.com/2022/08/06/interview_ransomware_negotiator/
[11] https://whitepapers.theregister.com/
Today we learned
fidodogbreath
that Twilio doesn't use 2FA to protect accounts with privileged access to their backend systems and customer data.
Doctor Syntax
Give an incorrect password the first time. The fake site has to believe it. If it was accepted then (a) you don't give a real one, (b) you can raise the alarm and (bc the scallies have duff data,
Sophisticated
A lot of my users have been getting very targeted phishes claiming to be from managers, along with sigs matching the sender's actual titles, etc. Figured out it's just harvested from LinkedIn. Hard to protect people when they self-publish everything needed to pretend to be them.