Desk live·
ForensicPost
Breaches/Identity/File 22-0808

Same Phish, Same Week, Two Companies, Two Outcomes

The 0ktapus campaign texted employees at over 130 organisations. At Twilio, credentials entered on a fake login page reached internal systems. At Cloudflare, three employees also clicked — and the attack stopped, because the second factor was a physical key.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTwilio
Actor0ktapus
S. Rosler12 min readConfidence: high2 sources reviewed

In August 2022 a campaign researchers named 0ktapus sent SMS messages to employees at more than 130 organisations, impersonating internal IT and claiming passwords had expired or shifts had changed. The messages linked to convincing fake login pages.

At Twilio, the credentials worked: attackers reached internal systems and customer data, with 209 customers and 93 Authy end users reported affected. At Cloudflare, three employees clicked the link and entered credentials — and no systems were reached. Cloudflare issued FIDO2 physical security keys to every employee and required them for application access.

This Is The Controlled Experiment

The corpus argues about authentication factors constantly and almost never gets to compare them cleanly. Here the campaign, the pretext, the infrastructure and the week are held constant. Employees at both companies fell for it. Only the second factor differs.

A one-time code is a string the user reads and types, so it can be relayed to a real login page by whoever is standing in the middle. A FIDO2 key performs a cryptographic operation bound to the origin it is talking to, so presented with a lookalike domain it produces something the real site will not accept. The user’s judgement is removed from the outcome, which is the point.

Clicking Was Not The Failure

Three Cloudflare employees clicked and typed their password into an attacker’s page. Under most security-awareness framing, that is the failure and those three people are the problem.

They were not. The control absorbed it. The corpus records the opposite arrangement at 22-0915, where a factor asked a tired contractor a yes-or-no question at the wrong moment, and at 23-0913, where a synced authenticator turned a second factor into no factor. A system that depends on nobody ever clicking is not a system.

And It Reached 130 Organisations

The campaign is filed here under two names because it is one operation. Reported downstream targets include Signal and DoorDash, and the corpus records the same social-engineering pattern maturing at 26-0714 and in the Scattered Spider files at 26-0725 and 26-0716b.

The technique did not need to be sophisticated. It needed a phone number list and a plausible sentence, which is the durable finding: the cost of running this scales with SMS, and the cost of resisting it is a hardware purchase most organisations still have not made.

How we reported this

Built on contemporaneous reporting and vendor analysis of the 0ktapus campaign, including Cloudflare’s own account of the attempt against it. The SMS pretexts, the >130 organisations figure, Twilio’s compromise and the 209 customers / 93 Authy end users figures, and Cloudflare’s report that three employees entered credentials while FIDO2 keys prevented access are as reported. The explanation of why origin-bound authentication resists relay is this desk’s, from the design of the standard, and is presented as reasoning rather than as a claim about these incidents. Attribution to a single actor cluster is as reported by researchers and is carried as attribution. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Twilio Hackers Scarf 10K Okta Credentials in Sprawling Supply Chain AttackDark Reading
  2. Cloudflare And Twilio Targets Of A Sophisticated Smishing AttackPurpleSec
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary