What happened
On 20 July 2022 Cloudflare employees and some of their family members received more than 100 text messages within about a minute pointing to a fake Okta login page at cloudflare-okta.com, a domain registered less than 40 minutes earlier. Three employees entered credentials, but the attack failed: Cloudflare issues every employee a FIDO2-compliant hardware security key, and origin binding prevented the attackers from completing a login.
How the deception worked
The SMS lures directed staff to a convincing clone of Cloudflare's Okta sign-in page. Credentials typed into the clone were relayed in real time over Telegram, and the page also prompted for the second factor so operators could complete the login within the code's validity window. It additionally attempted to push AnyDesk remote access software to visitors for persistence if the credential path failed. Three employees submitted credentials, but the hardware keys are bound to the legitimate origin and would not produce a valid assertion for the attacker's domain, so no session was ever established. Cloudflare Gateway also blocked the malicious domain on corporate devices, and none of the targets installed the remote access tool.
AI involvement · No AI reported
No AI element reported.
The control that would have caught it· our reading, not a claim from the sources
This is the control demonstration for the whole category: origin-bound hardware security keys make credential relay structurally impossible, regardless of how convincing the lure is.
Sources (3)
- The mechanics of a sophisticated phishing scam and how we stopped itCloudflare Blog·blog.cloudflare.comOpen ↗
- Cloudflare employees also hit by hackers behind Twilio breachBleepingComputer·bleepingcomputer.comOpen ↗
- Cloudflare scuppers Twilio-like cyber attack with hardware keysIT Pro·itpro.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.