0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies
Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.
In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of them customers of identity provider Okta — and was linked to breaches at Twilio, Cloudflare (attempted), DoorDash, Mailchimp and others.
How it worked
Attackers sent SMS messages to employees, often claiming their schedule had changed or their account needed attention, with links to convincing phishing pages imitating the company's Okta sign-in. Victims entered their username, password and one-time MFA code, which attackers relayed in real time. Group-IB estimated nearly 10,000 credentials were captured.
At Twilio, attackers accessed internal systems and data for a number of customers — including, notably, data used by the encrypted messaging app Signal to register phone numbers.
The Cloudflare exception
Cloudflare disclosed that three of its employees fell for the same phishing messages — but attackers couldn't log in. Cloudflare required FIDO2 hardware security keys for employee authentication. The keys wouldn't authenticate to the phishing site, so the stolen passwords and codes were useless. Cloudflare's write-up became one of the most cited arguments for phishing-resistant MFA.
Why it mattered
0ktapus combined SMS phishing with real-time MFA relay, at scale, against technology companies with mature security programs. It was attributed to a group later known as Scattered Spider, which went on to the 2023 MGM and Caesars attacks.
Lessons in hindsight
- One-time codes can be phished; hardware keys and passkeys can't.
- SMS lures to personal phones bypass corporate email filters.
- Supply-chain effects: breaching Twilio exposed its customers.
- Phishing-resistant MFA is a business decision, not an IT preference.
- How to Deploy FIDO2 Security Keys for High-Risk Users How-To & Hardening
- Detecting SMS Phishing Credential Harvesting: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: The Case for Hardware Security Keys CIO Briefings