In August 2022 a campaign researchers named 0ktapus sent SMS messages to employees at more than 130 organisations, impersonating internal IT and claiming passwords had expired or shifts had changed. The messages linked to convincing fake login pages.
At Twilio, the credentials worked: attackers reached internal systems and customer data, with 209 customers and 93 Authy end users reported affected. At Cloudflare, three employees clicked the link and entered credentials — and no systems were reached. Cloudflare issued FIDO2 physical security keys to every employee and required them for application access.
This Is The Controlled Experiment
The corpus argues about authentication factors constantly and almost never gets to compare them cleanly. Here the campaign, the pretext, the infrastructure and the week are held constant. Employees at both companies fell for it. Only the second factor differs.
A one-time code is a string the user reads and types, so it can be relayed to a real login page by whoever is standing in the middle. A FIDO2 key performs a cryptographic operation bound to the origin it is talking to, so presented with a lookalike domain it produces something the real site will not accept. The user’s judgement is removed from the outcome, which is the point.
Clicking Was Not The Failure
Three Cloudflare employees clicked and typed their password into an attacker’s page. Under most security-awareness framing, that is the failure and those three people are the problem.
They were not. The control absorbed it. The corpus records the opposite arrangement at 22-0915, where a factor asked a tired contractor a yes-or-no question at the wrong moment, and at 23-0913, where a synced authenticator turned a second factor into no factor. A system that depends on nobody ever clicking is not a system.
And It Reached 130 Organisations
The campaign is filed here under two names because it is one operation. Reported downstream targets include Signal and DoorDash, and the corpus records the same social-engineering pattern maturing at 26-0714 and in the Scattered Spider files at 26-0725 and 26-0716b.
The technique did not need to be sophisticated. It needed a phone number list and a plausible sentence, which is the durable finding: the cost of running this scales with SMS, and the cost of resisting it is a hardware purchase most organisations still have not made.
Built on contemporaneous reporting and vendor analysis of the 0ktapus campaign, including Cloudflare’s own account of the attempt against it. The SMS pretexts, the >130 organisations figure, Twilio’s compromise and the 209 customers / 93 Authy end users figures, and Cloudflare’s report that three employees entered credentials while FIDO2 keys prevented access are as reported. The explanation of why origin-bound authentication resists relay is this desk’s, from the design of the standard, and is presented as reasoning rather than as a claim about these incidents. Attribution to a single actor cluster is as reported by researchers and is carried as attribution. Graded high. Corrections: corrections@forensicpost.com.