{"id":1237801,"date":"2022-10-29T06:45:52","date_gmt":"2022-10-29T06:45:52","guid":{"rendered":"https:\/\/www.ghanamma.com\/2022\/10\/29\/twilio-hack-investigation-reveals-second-breach-as-the-number-of-affected-customers-rises\/"},"modified":"2022-10-29T06:45:52","modified_gmt":"2022-10-29T06:45:52","slug":"twilio-hack-investigation-reveals-second-breach-as-the-number-of-affected-customers-rises","status":"publish","type":"post","link":"https:\/\/www.ghanamma.com\/2022\/10\/29\/twilio-hack-investigation-reveals-second-breach-as-the-number-of-affected-customers-rises\/","title":{"rendered":"Twilio hack investigation reveals second breach, as the number of affected customers rises \u2022"},"content":{"rendered":"<p><\/p>\n<div>\n<p id=\"speakable-summary\">U.S. messaging giant Twilio confirmed it was hit by a second breach in June that saw cybercriminals access customer contact information.<\/p>\n<p>Confirmation of the second breach \u2014 carried out by the same \u201c0ktapus\u201d hackers that compromised Twilio again in August \u2014 was buried in an update to a lengthy incident report that Twilio concluded on Thursday.<\/p>\n<p>Twilio said the \u201cbrief security incident,\u201d which occurred on June 29, saw the same attackers socially engineer an employee through voice phishing, a tactic whereby hackers make fraudulent phone calls impersonating the company\u2019s IT department in an effort to trick employees into handing over sensitive information. In this case, the Twilio employee provided their corporate credentials, enabling the attacker to access customer contact information for a \u201climited number\u201d of customers.<\/p>\n<p>\u201cThe threat actor\u2019s access was identified and eradicated within 12 hours,\u201d Twilio said in its update, adding that customers whose information was impacted by the June incident were notified on July 2.<\/p>\n<p>When asked by , Twilio spokesperson Laurelle Remzi declined to confirm the exact number of customers impacted by the June breach and declined to share a copy of the notice that the company claims to have sent to those affected. Remzi also declined to say why Twilio has only just disclosed the incident.<\/p>\n<p>Twilio also confirmed in its update that the hackers behind the August breach accessed the data of 209 customers, an increase from 163 customers it shared on August 24. Twilio has not named any of its impacted customers, but some \u2014 like encrypted messaging app Signal \u2014 have notified users that they were affected by Twilio\u2019s breach. The attackers also compromised the accounts of 93 Authy users, Twilio\u2019s two-factor authentication app it acquired in 2015.<\/p>\n<p>\u201cThere is no evidence that the malicious actors accessed Twilio customers\u2019 console account credentials, authentication tokens, or API keys,\u201d Twilio said about the attackers, which maintained access to Twilio\u2019s internal environment for two days between August 7 and August 9, the company confirmed.<\/p>\n<p>The Twilio breach is part of a wider campaign from a threat actor tracked as \u201c0ktapus,\u201d which targeted at least 130 organizations, including Mailchimp and Cloudflare. But Cloudflare said the attackers failed to compromise its network after having their attempts blocked by phishing-resistant hardware security keys.<\/p>\n<p>As part of its efforts to mitigate the efficacy of similar attacks in the future, Twilio has announced that it will also roll out hardware security keys to all employees. Twilio declined to comment on its rollout timeline.\u00a0The company says it also plans to implement additional layers of control within its VPN, remove and limit certain functionality within specific administrative tooling, and increase the refresh frequency of tokens for Okta-integrated applications.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>U.S. messaging giant Twilio confirmed it was hit by a second breach in June that saw cybercriminals access customer contact information. Confirmation of the second breach \u2014 carried out by the same \u201c0ktapus\u201d hackers that compromised Twilio again in August \u2014 was buried in an update to a lengthy incident report that Twilio concluded on [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1237803,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[21],"tags":[],"class_list":["post-1237801","post","type-post","status-publish","format-standard","has-post-thumbnail","category-celebrity-gossip"],"_links":{"self":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1237801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/comments?post=1237801"}],"version-history":[{"count":0,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/posts\/1237801\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/media?parent=1237801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/categories?post=1237801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ghanamma.com\/2022\/wp-json\/wp\/v2\/tags?post=1237801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}