Case file · TWILIO 2022

How the Twilio breach happened, and why Cloudflare shrugged off the same texts

Published 2026-09-29 · 5 min read · Missing control: Phishing-resistant hardware security keys

In the summer of 2022, employees at two tech companies got the same kind of fake text and some at both companies typed their passwords into the same kind of fake login page. One company was breached and its customers were hit downstream; the other lost nothing.[1][3] This case file covers the campaign, why the outcomes split, and the one control that made the difference.

What happened

On July 20, 2022, at least 76 Cloudflare employees and some of their family members received text messages pointing to a login page that looked like the company's own. The web address for that page had been registered less than 40 minutes before the texts went out. 3 employees entered their usernames and passwords.[1]

Around the same time, Twilio employees received similar texts claiming to come from IT, saying their password had expired or their schedule had changed, with links to lookalike login pages. Some of them also entered their credentials. Twilio detected unauthorized access on August 4, 2022, and the last unauthorized activity it saw was on August 9.[2]

At Cloudflare, the stolen passwords opened nothing. At Twilio, the attackers got into internal systems, including tools that let them see customer data. Twilio's final count was 209 customer accounts out of more than 270,000, plus 93 users of its Authy two-factor app, where the attackers added their own devices to victims' accounts.[2]

How they got in

The fake pages were built to capture more than a password. When someone typed their credentials, the details were relayed to the attackers in real time, and the page then asked for the 6-digit one-time code from the employee's authenticator app.[1][3] Those codes are valid for about 30 seconds, which is plenty of time for an attacker who is watching live and logs in straight away. A text or app code proves you have your phone. It does not prove you are on the real website.

That is where Cloudflare's setup parted ways. Every Cloudflare employee carried a physical security key, a small USB or tap-to-use device built on the FIDO2 standard, and every login required it.[1][3] These keys check the web address they are talking to. On a fake site, the key simply will not sign in, so there is nothing to type and nothing for the attacker to steal. The 3 employees who were fooled still could not hand over a working login.[1]

Twilio's employees had no such key in the loop, so a password plus a code was enough. From inside Twilio, the attackers could reach its customers. Signal, the messaging app, said about 1,900 of its users' phone numbers were exposed, and that the attackers could have tried to register those numbers to another device using a text verification code. Signal said one account was actually taken over, and that message history and contacts, which live only on users' phones, were not exposed.[4]

What it cost

Twilio was one of many. Researchers found the same crew had targeted more than 130 organizations and collected about 10,000 employee logins, and Okta said the attackers had obtained some of its customers' phone numbers and one-time codes through Twilio.[5] Twilio said it saw no evidence that customer passwords, authentication tokens or API keys were taken.[2]

In November 2024, federal prosecutors in Los Angeles charged 5 men they said belonged to the group and said it had used its access to Twilio to go after at least 163 of Twilio's customers.[6] One of them pleaded guilty and was sentenced in August 2025 to 10 years in federal prison and $13 million in restitution; the summer 2022 texting campaign was part of the conduct covered.[7] The others were charged, not convicted, as of the reports reviewed here.

Cloudflare's cost was a few password resets. It also tightened access rules and worked to take the attackers' server offline.[3] Twilio's fix afterward was to issue FIDO2 security keys to all of its employees.[2]

The missing control

The missing control: phishing-resistant hardware security keys. Twilio relied on passwords and one-time codes, both of which a person can be tricked into typing into a fake page.

Training helps, but both companies proved that some people will click on a well-timed text. The Cloudflare result shows the better goal: a login that still holds when someone is fooled. A key that only works on the genuine site turns a successful phishing text into a dead end. Twilio reached the same conclusion and made the change after the breach.[2]

What to do in your business

Watch the case
Same Phishing Texts, Two Companies, Two EndingsDrops 2026-11-06
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Security Affairs: Hackers behind Twilio data breach also targeted Cloudflare employees
  2. Twilio: Incident report, employee and customer account compromise
  3. The Hacker News: Hackers behind Twilio breach also targeted Cloudflare employees
  4. IT Pro: Signal confirms 1,900 of its users were hit by Twilio breach
  5. TechCrunch: Twilio breach also compromised Authy two-factor accounts
  6. Krebs on Security: Feds charge five men in Scattered Spider roundup
  7. Krebs on Security: SIM-swapper, Scattered Spider hacker gets 10 years