{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:09.560Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Cloudflare blocks the same SMS phishing attack that breached Twilio","date":"2022-07-20","date_precision":"day","victim_org":"Cloudflare","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Attempt Blocked","Credential Theft"],"loss_usd":null,"loss_note":"No loss; the intrusion attempt failed at the authentication step.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (same actor as the Twilio campaign)","summary":"On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.","how_it_worked":"The SMS lures directed staff to a convincing clone of Cloudflare's Okta sign-in page. Credentials typed into the clone were relayed in real time over Telegram, and the page also prompted for the second factor so operators could complete the login within the code's validity window. It additionally attempted to push AnyDesk remote access software to visitors for persistence if the credential path failed. Three employees submitted credentials, but the hardware keys are bound to the legitimate origin and would not produce a valid assertion for the attacker's domain, so no session was ever established. Cloudflare Gateway also blocked the malicious domain on corporate devices, and none of the targets installed the remote access tool.","lessons":"This is the control demonstration for the whole category: origin-bound hardware security keys make credential relay structurally impossible, regardless of how convincing the lure is.","confidence":"Confirmed","sources":[{"title":"The mechanics of a sophisticated phishing scam and how we stopped it","url":"https://blog.cloudflare.com/2022-07-sms-phishing-attacks/","publisher":"Cloudflare Blog"},{"title":"Cloudflare employees also hit by hackers behind Twilio breach","url":"https://www.bleepingcomputer.com/news/security/cloudflare-employees-also-hit-by-hackers-behind-twilio-breach/","publisher":"BleepingComputer"},{"title":"Cloudflare scuppers Twilio-like cyber attack with hardware keys","url":"https://www.itpro.com/security/cyber-security/368798/cloudflare-scuppers-twilio-like-cyber-attack-with-hardware-keys","publisher":"IT Pro"}],"entry_type":"incident","slug":"2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-cloudflare-blocks-the-same-sms-phishing-attack-that-breached-twilio"}]}