In mid-July 2022, actors posing as Twilio IT smished current and former employees with links to typosquat fake Okta login pages. Some employees entered credentials, and 0ktapus/Scatter Swine campaign tooling harvested OTP and 2FA codes in real time. According to Twilio's incident report, the company became aware of unauthorized access on 4 August 2022, last observed unauthorized activity on 9 August 2022, and closed the investigation with impact on 209 Twilio customers and 93 Authy end users. Public reporting does not establish how many employees submitted credentials on the fake pages.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
How did attackers get into Twilio in the 0ktapus incident?
The attackers got into Twilio by smishing employees with SMS messages that impersonated Twilio IT and linked to fake Okta login pages on typosquat domains. Some employees typed workforce credentials on those pages, and campaign tooling associated with 0ktapus/Scatter Swine captured OTP and 2FA codes in real time. That completed a legitimate-looking workforce sign-in path the attackers then used against internal admin tools. Public reporting does not establish the exact headcount of employees who submitted credentials.
Why didn't employee MFA stop the Twilio smishing?
Employee MFA did not stop the Twilio 0ktapus smishing because the second factor was a phishable OTP or 2FA code the victim typed on an attacker-controlled fake Okta page. Real-time harvest tooling collected those codes with the password, so legacy MFA finished the attacker's login instead of blocking it. Closing that phishable login stops this path. A fix for transferable-factor harvest exists; the prevention write-up is on the companion site.
What happened after the fake Okta logins succeeded?
After the fake Okta path succeeded, compromised access was used against Twilio internal admin tools, with unauthorized activity observed through 9 August 2022. According to Twilio's final investigation figures, that post-login access produced residual impact on 209 Twilio customers and 93 Authy end users. Once authentication had already succeeded, no MFA undoes session use or admin-tool data access. Public reporting does not establish a ransom demand for this incident.
Was the Twilio attack device-code phishing?
No. The Twilio 0ktapus path was smishing to fake Okta login pages with real-time credential and OTP harvest, not an OAuth device-code flow. Employees were steered onto typosquat IdP lookalikes and completed a password-plus-OTP ceremony the campaign tooling could capture live. That is a credential-phase failure at the login form, not a device-code approval on the real Microsoft or Okta authorize endpoint.
Is DoorDash the same campaign as Twilio 0ktapus?
Public reporting in the materials used here treats DoorDash vendor phishing as adjacent August 2022 phishing and social-engineering context only. It does not establish that DoorDash and the Twilio employee smishing shared the same actors or the same campaign. The Twilio path is documented as workforce smishing to fake Okta pages with live OTP harvest against Twilio employees, not as a proven multi-company single operation with DoorDash.