Three Cloudflare employees typed passwords into a fake Okta page after a mass SMS blast, and mandatory FIDO2 hardware keys still blocked every login. Attackers texted at least 76 employees and some family members on 20 July 2022 to newly registered cloudflare-okta.com, a lookalike built for real-time credential and TOTP relay. According to Cloudflare’s 9 August 2022 post-mortem, there was no account takeover and no Cloudflare systems were compromised.

For how hardware-bound keys close this path, see the companion on mfa2point0.com.

FAQ

What happened in Cloudflare’s July 2022 SMS phishing attack?

Attackers sent legitimate-looking SMS messages beginning at 22:50 UTC on 20 July 2022 to at least 76 Cloudflare employees, and some family members, pointing them at a fake Cloudflare Okta login on newly registered cloudflare-okta.com. According to Cloudflare’s blog, the messages went out over less than one minute, employees reported them to SIRT, and the phishing kit was built to relay credentials in real time and harvest TOTP. Three employees typed passwords on that phishing page. Cloudflare’s mandatory physical FIDO2 hardware keys still blocked login, and Cloudflare confirmed no systems were compromised.

Did password entry mean the attackers got in?

No. In the Cloudflare July 2022 incident, three employee passwords were entered on the phishing page, but that was not enough for account takeover. Cloudflare required physical FIDO2 hardware security keys for every employee to access all applications. Those keys need an origin-bound ceremony the fake Okta page could not complete, so harvested passwords never became a usable Okta session. Cloudflare stated: “We have confirmed that no Cloudflare systems were compromised.”

Was any TOTP code stolen from those three users?

Public reporting does not establish that TOTP codes were successfully captured from the three Cloudflare employees who entered passwords. Cloudflare described a phishing kit designed for real-time credential and TOTP relay. The decisive control was still mandatory FIDO2 hardware keys, which blocked authentication even after the password step succeeded on the lookalike page.

How is this different from the Twilio phishing case around the same time?

Cloudflare explicitly paired the incidents. On 8 August 2022, Twilio publicly shared a compromise by a targeted phishing attack with very similar SMS and phishing characteristics. Cloudflare’s contrast is straightforward: the same class of credential-relay tradecraft produced account takeover where equivalent phishing-resistant hardware keys were not in the path, while Cloudflare’s FIDO2 requirement stopped ATO before any Cloudflare system access. Public reporting in Cloudflare’s post-mortem does not publish full Twilio technical internals beyond that similarity and outcome contrast.

How did attackers get employee and family phone numbers?

Public reporting does not establish how the attacker assembled employee and family phone numbers. Cloudflare reviewed access logs to the employee directory and reported no sign of compromise explaining the sourcing. The open question is the contact list, not the login outcome: passwords were phishable on the fake Okta page, and FIDO2 still denied the session.