Security

Twilio hack investigation reveals second breach, as the number of affected customers rises

Comment

A fishing hook on a line on a red background featuring thick zeros and ones, representing binary code.
Image Credits: Getty Images

U.S. messaging giant Twilio confirmed it was hit by a second breach in June that saw cybercriminals access customer contact information.

Confirmation of the second breach — carried out by the same “0ktapus” hackers that compromised Twilio again in August — was buried in an update to a lengthy incident report that Twilio concluded on Thursday.

Twilio said the “brief security incident,” which occurred on June 29, saw the same attackers socially engineer an employee through voice phishing, a tactic whereby hackers make fraudulent phone calls impersonating the company’s IT department in an effort to trick employees into handing over sensitive information. In this case, the Twilio employee provided their corporate credentials, enabling the attacker to access customer contact information for a “limited number” of customers.

“The threat actor’s access was identified and eradicated within 12 hours,” Twilio said in its update, adding that customers whose information was impacted by the June incident were notified on July 2.

When asked by TechCrunch, Twilio spokesperson Laurelle Remzi declined to confirm the exact number of customers impacted by the June breach and declined to share a copy of the notice that the company claims to have sent to those affected. Remzi also declined to say why Twilio has only just disclosed the incident.

Twilio also confirmed in its update that the hackers behind the August breach accessed the data of 209 customers, an increase from 163 customers it shared on August 24. Twilio has not named any of its impacted customers, but some — like encrypted messaging app Signal — have notified users that they were affected by Twilio’s breach. The attackers also compromised the accounts of 93 Authy users, Twilio’s two-factor authentication app it acquired in 2015.

“There is no evidence that the malicious actors accessed Twilio customers’ console account credentials, authentication tokens, or API keys,” Twilio said about the attackers, which maintained access to Twilio’s internal environment for two days between August 7 and August 9, the company confirmed.

The Twilio breach is part of a wider campaign from a threat actor tracked as “0ktapus,” which targeted at least 130 organizations, including Mailchimp and Cloudflare. But Cloudflare said the attackers failed to compromise its network after having their attempts blocked by phishing-resistant hardware security keys.

As part of its efforts to mitigate the efficacy of similar attacks in the future, Twilio has announced that it will also roll out hardware security keys to all employees. Twilio declined to comment on its rollout timeline. The company says it also plans to implement additional layers of control within its VPN, remove and limit certain functionality within specific administrative tooling, and increase the refresh frequency of tokens for Okta-integrated applications.

Twilio hackers breached over 130 organizations during months-long hacking spree

More TechCrunch

The AI boom is fueling the demand for data centers and, in turn, driving up water consumption. (Water is used to cool the computing equipment inside data centers.) According to…

Demand for AI is driving data center water consumption sky high

The group honking was an unintended consequence of Waymo’s tech.

The Waymo robotaxi honking problem has been resolved for real this time

OpenAI and Anthropic spend billions of dollars a year training models like GPT-4 and Claude, but competitive price dumping is making the business around these platforms rather precarious. Aidan Gomez,…

What margins? AI’s business model is changing fast, says Cohere founder

Hello, and welcome back to TechCrunch Space. Did you hear? Bridgit Mendler will be joining me onstage at this year’s TechCrunch Disrupt to talk all things ground stations. She’s just…

TechCrunch Space: Spending less

What’s the point of chatting with a human-like bot if it’s an unreliable narrator — and has a colorless personality? That’s the question I’ve been turning over in my head…

Gemini Live could use some more rehearsals

Zoom on Monday announced a new single-user webinar feature that caps out at 1 million attendees. The addition comes less than a month after the #WinWithBlackWomen fundraiser for Vice President…

Now a million people can watch you fumble Zoom’s screen-share settings at once

On Sunday, former President Donald Trump posted a collection of memes on Truth Social — the platform owned by his media company — that make it seem like Taylor Swift…

Could Trump’s AI-generated Taylor Swift endorsement be illegal?

Few truly autonomous systems are deployed on the battlefield, but one startup is looking to change that with robotic systems that use cooperative behavior to boost troops’ intelligence and tactical…

Swarmbotics founders grew ‘obsessed with robot swarms’ and now plan to bring them to the battlefield

Former a16z-investor Balaji Srinivasan has booked out an island in Singapore to create his own “Network School.”

Former a16z VC Balaji Srinivasan obtained a private island for his new longevity ‘technocapitalist’ school

The flight tracking company says the misconfiguration exposed customer names, addresses, and pilot’s data, as well as Social Security numbers.

FlightAware warns that some customers’ info has been ‘exposed,’ including Social Security numbers

Over 30% of 7- to 9-year-olds have an X account, according to a new report.

A surprising number of ‘iPad Kids’ are on X, study finds

Apple Podcasts can now be streamed from the web. Apple announced on Monday that its Apple Podcasts app is now available on all major web browsers (Chrome, Edge, Firefox, and…

Apple Podcasts launches on the web

Historic vehicles, flowing champagne and fashion have dominated the events at Monterey Car Week for decades now. But a change is afoot: EVs, tech-centric vehicles, startups and a heavy dose…

From a $2.5 million hyper car to a Spanish track-ready EV, here were the most interesting EVs at Monterey Car Week

The clock is ticking! You’ve got just 5 days left to lock in discounted tickets for TechCrunch Disrupt 2024. Save up to $600 on individual ticket types. This limited-time offer ends…

5 days left to secure ticket savings for TechCrunch Disrupt 2024

General Motors is cutting around 1,000 software workers around the world in a bid to focus on more “high-priority” initiatives like improving its Super Cruise driver assistance system, the quality…

GM cuts 1,000 software jobs as it prioritizes quality and AI

Popular iPad design app Procreate is coming out against generative AI, and has vowed never to introduce generative AI features into its products. The company said on its website that…

Procreate takes a stand against generative AI, vows to never incorporate the tech into its products

Mike Lynch, the investor and high-profile founder of U.K. tech firm Autonomy, has been declared missing at sea after the yacht he was on, the Bayesian, capsized in a storm…

Mike Lynch, recently acquitted in HP-Autonomy fraud case, is missing after yacht capsized off Sicily

ElevenLabs, which develops AI-powered tools to create and edit synthetic voices, is making its Reader app available globally with support for 32 languages.

ElevenLabs’ text-to-speech app Reader is now available globally

AMD is acquiring ZT Systems, which provides compute design and infrastructure for AI, cloud and general purpose computing, for $4.9 billion.

AMD to acquire infrastructure player ZT Systems for $4.9B to amp up its AI ecosystem play

Amazon is considering shifting its payments offerings in India into a standalone app, three sources familiar with the matter told TechCrunch, as the e-commerce giant aims to boost usage of…

Amazon considers moving Amazon Pay into a standalone app in India

Root helps food and beverage companies collect primary data on their agricultural supply chains. 

As CO2 emissions from supply chains come into focus, this startup is aiming at farms

In May, the African fintech processed up to $70 million in monthly payment volume.

Waza comes out of stealth with $8M to power global trade for African businesses

This post contains spoilers for the movie “Alien: Romulus” In the long-running “Alien” movie franchise, the Weyland-Yutani Corporation can’t seem to let go of a terrible idea: It keeps trying…

Digitally resurrecting actors is still a terrible idea

Thomas Ingenlath is having perhaps a little too much fun in his Polestar 3, silently rocketing away from stop signs and swinging through tightening bends, grinning like a man far…

With the Polestar 3 now ‘weeks’ away, its CEO looks to make company ‘self-sustaining’

Some parents have reservations about the South Korean government’s plans to bring tablets with AI-powered textbooks into classrooms, according to a report in Financial Times. The tablets are scheduled to…

South Korea’s AI textbook program faces skepticism from parents

Featured Article

How VC Pippa Lamb ended up on ‘Industry’ — one of the hottest shows on TV

Season 3 of “Industry” focuses on the fictional bank Pierpoint and blends the worlds — and drama — of tech, media, government and finance.

How VC Pippa Lamb ended up on ‘Industry’ — one of the hottest shows on TV

Featured Article

Selling a startup in an ‘acqui-hire’ is more lucrative than it seems, founders and VCs say

Selling under such circumstances is often not as poor of an outcome for founders and key staff as it initially seems. 

Selling a startup in an ‘acqui-hire’ is more lucrative than it seems, founders and VCs say

While the rapid pace of funding has slowed, many fintechs are continuing to see growth and expand their teams.

These  fintech companies are hiring, despite a rough market in 2024

This is just one area of leadership where Parker Conrad takes a contrarian approach. He also said he doesn’t believe in top-down management.

Rippling’s Parker Conrad says founders should ‘go all the way to the ground’ to run their companies

Congresswoman Nancy Pelosi issued a statement late yesterday laying out her opposition to SB 1047, a California bill that seeks to regulate AI. “The view of many of us in…

Nancy Pelosi criticizes California AI bill as ‘ill-informed’