Entra ID & IdentityIncident TeardownsRetrospectives

0ktapus and the Twilio Breach (Aug 2022): SMS Phishing Against 130+ Companies

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2022, written in 2026 with the benefit of hindsight.

In August 2022, researchers at Group-IB described a phishing campaign they named 0ktapus. It targeted employees of more than 130 organizations — many of them customers of identity provider Okta — and was linked to breaches at Twilio, Cloudflare (attempted), DoorDash, Mailchimp and others.

How it worked

Attackers sent SMS messages to employees, often claiming their schedule had changed or their account needed attention, with links to convincing phishing pages imitating the company's Okta sign-in. Victims entered their username, password and one-time MFA code, which attackers relayed in real time. Group-IB estimated nearly 10,000 credentials were captured.

At Twilio, attackers accessed internal systems and data for a number of customers — including, notably, data used by the encrypted messaging app Signal to register phone numbers.

The Cloudflare exception

Cloudflare disclosed that three of its employees fell for the same phishing messages — but attackers couldn't log in. Cloudflare required FIDO2 hardware security keys for employee authentication. The keys wouldn't authenticate to the phishing site, so the stolen passwords and codes were useless. Cloudflare's write-up became one of the most cited arguments for phishing-resistant MFA.

Why it mattered

0ktapus combined SMS phishing with real-time MFA relay, at scale, against technology companies with mature security programs. It was attributed to a group later known as Scattered Spider, which went on to the 2023 MGM and Caesars attacks.

Lessons in hindsight

  • One-time codes can be phished; hardware keys and passkeys can't.
  • SMS lures to personal phones bypass corporate email filters.
  • Supply-chain effects: breaching Twilio exposed its customers.
  • Phishing-resistant MFA is a business decision, not an IT preference.
0ktapus0ktapus / Twilio2022

More on this story