How the Twilio breach happened, and why Cloudflare shrugged off the same texts
In the summer of 2022, employees at two tech companies got the same kind of fake text and some at both companies typed their passwords into the same kind of fake login page. One company was breached and its customers were hit downstream; the other lost nothing.[1][3] This case file covers the campaign, why the outcomes split, and the one control that made the difference.
What happened
On July 20, 2022, at least 76 Cloudflare employees and some of their family members received text messages pointing to a login page that looked like the company's own. The web address for that page had been registered less than 40 minutes before the texts went out. 3 employees entered their usernames and passwords.[1]
Around the same time, Twilio employees received similar texts claiming to come from IT, saying their password had expired or their schedule had changed, with links to lookalike login pages. Some of them also entered their credentials. Twilio detected unauthorized access on August 4, 2022, and the last unauthorized activity it saw was on August 9.[2]
At Cloudflare, the stolen passwords opened nothing. At Twilio, the attackers got into internal systems, including tools that let them see customer data. Twilio's final count was 209 customer accounts out of more than 270,000, plus 93 users of its Authy two-factor app, where the attackers added their own devices to victims' accounts.[2]
How they got in
The fake pages were built to capture more than a password. When someone typed their credentials, the details were relayed to the attackers in real time, and the page then asked for the 6-digit one-time code from the employee's authenticator app.[1][3] Those codes are valid for about 30 seconds, which is plenty of time for an attacker who is watching live and logs in straight away. A text or app code proves you have your phone. It does not prove you are on the real website.
That is where Cloudflare's setup parted ways. Every Cloudflare employee carried a physical security key, a small USB or tap-to-use device built on the FIDO2 standard, and every login required it.[1][3] These keys check the web address they are talking to. On a fake site, the key simply will not sign in, so there is nothing to type and nothing for the attacker to steal. The 3 employees who were fooled still could not hand over a working login.[1]
Twilio's employees had no such key in the loop, so a password plus a code was enough. From inside Twilio, the attackers could reach its customers. Signal, the messaging app, said about 1,900 of its users' phone numbers were exposed, and that the attackers could have tried to register those numbers to another device using a text verification code. Signal said one account was actually taken over, and that message history and contacts, which live only on users' phones, were not exposed.[4]
What it cost
Twilio was one of many. Researchers found the same crew had targeted more than 130 organizations and collected about 10,000 employee logins, and Okta said the attackers had obtained some of its customers' phone numbers and one-time codes through Twilio.[5] Twilio said it saw no evidence that customer passwords, authentication tokens or API keys were taken.[2]
In November 2024, federal prosecutors in Los Angeles charged 5 men they said belonged to the group and said it had used its access to Twilio to go after at least 163 of Twilio's customers.[6] One of them pleaded guilty and was sentenced in August 2025 to 10 years in federal prison and $13 million in restitution; the summer 2022 texting campaign was part of the conduct covered.[7] The others were charged, not convicted, as of the reports reviewed here.
Cloudflare's cost was a few password resets. It also tightened access rules and worked to take the attackers' server offline.[3] Twilio's fix afterward was to issue FIDO2 security keys to all of its employees.[2]
The missing control
The missing control: phishing-resistant hardware security keys. Twilio relied on passwords and one-time codes, both of which a person can be tricked into typing into a fake page.
Training helps, but both companies proved that some people will click on a well-timed text. The Cloudflare result shows the better goal: a login that still holds when someone is fooled. A key that only works on the genuine site turns a successful phishing text into a dead end. Twilio reached the same conclusion and made the change after the breach.[2]
What to do in your business
- Buy keys for your most important logins. Start with email admins, the finance team, and anyone who can reach bank or payroll accounts. Most major email and cloud services support them.
- Register 2 keys per person. Keep a spare in a safe place so a lost key does not become a lockout or a reason to turn security off.
- Retire text-message codes where you can. Once keys or passkeys are working, remove texts as a fallback for admin accounts, since attackers aim for the weakest option left.
- Tell staff IT will never text a login link. Put it in writing, and give them one known way to check a message, such as calling a number they already have.
- Make reporting easy and blame-free. Cloudflare moved fast because employees reported the texts. Thank people who report, even when they already clicked.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Security Affairs: Hackers behind Twilio data breach also targeted Cloudflare employees
- Twilio: Incident report, employee and customer account compromise
- The Hacker News: Hackers behind Twilio breach also targeted Cloudflare employees
- IT Pro: Signal confirms 1,900 of its users were hit by Twilio breach
- TechCrunch: Twilio breach also compromised Authy two-factor accounts
- Krebs on Security: Feds charge five men in Scattered Spider roundup
- Krebs on Security: SIM-swapper, Scattered Spider hacker gets 10 years