Skip to content

Twilio

Disclosed Aug 7, 20224 years agoConfirmed

Official notice

SMS phishing of employees gives 0ktapus hackers access to Twilio customer data

Twilio said attackers used text-message phishing to steal employee credentials and accessed data of a limited number of customer accounts; it later put the count at 209 customers and disclosed a separate June 2022 incident by the same group.

What is known

People affectedNot stated in the sources we have
DisclosedAug 7, 2022
DiscoveredAug 4, 2022
AttackPhishing
Data exposedNames, Emails, Phone numbers, Other
SectorTelecom · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
ResearchtotalAug 7, 2022

Other breaches at Twilio

BreachAffected
Unauthenticated Authy endpoint let attackers enumerate 33 million phone numbersJul 1, 20242 years agoScrapingUnverifiedUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Twilio

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.