{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:35.687Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Twilio breached by 0ktapus SMS phishing kit that hit 163 downstream customers","date":"2022-08-04","date_precision":"day","victim_org":"Twilio","sector":"Technology","country":"United States","primary_vector":"Smishing (SMS)","secondary_vectors":["Credential Phishing Portal","Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported; the kit relayed credentials to operators via Telegram in real time.","outcomes":["Data Breach","Credential Theft","Supply Chain Compromise"],"loss_usd":null,"loss_note":"No aggregate loss figure published across the affected organisations.","records_affected":null,"threat_actor":"Scatter Swine / 0ktapus (tracked by Okta and Group-IB; overlaps with Scattered Spider reporting)","summary":"In August 2022 Twilio disclosed that attackers had phished employee credentials by SMS and used them to access internal applications and a number of customer accounts. Okta's analysis of the actor, which it tracks as Scatter Swine, confirmed that 163 Twilio customers were affected, including Okta itself, and Twilio later said Authy two-factor app users were also touched. The same kit was used against more than a hundred organisations.","how_it_worked":"The actor sent bulk SMS lures to employees and in some cases their family members, warning of expired passwords or schedule changes and linking to domains built from templates such as company-okta.com or company-vpn.net. The pages cloned the target's real single sign-on portal and relayed submitted usernames and passwords to the operators over Telegram within seconds. Because the stolen credentials arrived live, operators could immediately trigger an SMS one-time-passcode challenge and, in Twilio's case, use console access to read the passcodes sent during those challenges, defeating SMS-based MFA and reaching internal systems and customer data.","lessons":"SMS one-time passcodes are relayable in real time; only origin-bound authenticators such as FIDO2 keys stop this kit, and lookalike-domain monitoring shortens the detection window.","confidence":"Confirmed","sources":[{"title":"Detecting Scatter Swine: Insights into a Relentless Phishing Campaign","url":"https://sec.okta.com/articles/scatterswine/","publisher":"Okta Security"},{"title":"Twilio confirms data breach after its employees got phished","url":"https://www.helpnetsecurity.com/2022/08/09/twilio-phished-data-breach/","publisher":"Help Net Security"},{"title":"Twilio says breach also compromised Authy two-factor app users","url":"https://techcrunch.com/2022/08/26/twilio-breach-authy/","publisher":"TechCrunch"},{"title":"Incident Report: Employee and Customer Account Compromise","url":"https://www.twilio.com/en-us/blog/archive/2022/august-2022-social-engineering-attack","publisher":"Twilio"}],"entry_type":"incident","slug":"2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust","year":2022,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2022-twilio-breached-by-0ktapus-sms-phishing-kit-that-hit-163-downstream-cust"}]}