{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org"},"incident":{"slug":"2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org","title":"0ktapus SMS phishing campaign harvested 9,931 credentials across 130 organisations","date":"2022-08","date_precision":"month","year":2022,"victim_org":"Over 130 organisations targeted (Group-IB tracked campaign)","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Supply Chain Compromise"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":9931,"threat_actor":"0ktapus (linked to Scattered Spider / UNC3944 activity)","summary":"Group-IB published research in August 2022 on a phishing campaign it named 0ktapus, which targeted more than 130 organisations, predominantly software, telecom and business services firms. The attackers harvested 9,931 user credentials and 5,441 multi-factor authentication codes through counterfeit Okta identity pages delivered by SMS. Publicly confirmed downstream victims of the same campaign included Twilio, Cloudflare, DoorDash and Mailchimp, with Signal users affected via Twilio.","how_it_worked":"Employees received text messages, often outside working hours, claiming their VPN session had expired or that a schedule change required immediate action, with a link to what looked like their employer's Okta single sign-on page. The pages were cloned per target company, so each recipient saw their own branding. Victims typed their username, password and then the one-time MFA code, all of which were relayed to the operators in real time and used to log in before the code expired. SMS was chosen deliberately: it arrives on a phone, outside corporate email defences, and reads as urgent IT housekeeping rather than an attack.","lessons":"Only phishing-resistant authentication such as FIDO2 security keys defeats a real-time relay of passwords and one-time codes; SMS-delivered lures also need out-of-band IT verification channels staff actually know to use.","confidence":"Confirmed","sources":[{"title":"Roasting 0ktapus: The phishing campaign going after Okta identity credentials","url":"https://www.group-ib.com/blog/0ktapus/","publisher":"Group-IB"},{"title":"0ktapus Phishing Campaign Targets Okta Identity Credentials","url":"https://www.infosecurity-magazine.com/news/0ktapus-phishing-targets-okta/","publisher":"Infosecurity Magazine"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-0ktapus-sms-phishing-campaign-harvested-9-931-credentials-across-130-org"}}