4 ms·
I can't be the only one laughing that Twilio employees were phished with SMS messages.
by hatware 4y ago
I can't be the only one laughing that Twilio employees were phished with SMS messages.
- Justin_K 4y agoIt's funny because they open by calling it a "sophisticated" attack... just not true.
- Raed667 4y agoAn attack is sophisticated when you don't want to get sued.
- hn_throwaway_99 4y ago> Additionally, the threat actors seemed to have sophisticated abilities to match employee names from sources with their phone numbers. Exactly, that is absolutely not sophisticated - it's often as simple as "scraping LinkedIn".
- karamanolev 4y agoI guess BigCorp will call anything that compromises them "sophisticated". They wouldn't admit being compromised by a technologically simple decades-old attack, would they?
- mattbee 4y agoKudos to them for showing the kind of messages that caught their own employees out - though to me they seem jarring and unsophisticated. So what other texts must Twilio send their own staff that make these ones feel legit? And what systems do they have online allowing for stolen employee credentials to be tested and used?
- madeofpalk 4y agoSend thousands of these out. You just need one person to be on auto-pilot mode to fall for it.
- mattbee 4y agoAh I'm sure, but their incident report mentions that an attacker has a list of employee names & numbers like that's top secret, but the question of how an attacker could then test stolen credentials seems far more interesting.
- kelnos 4y agoNot sure what you mean. These attacks work by getting a victim to click on a URL that leads to a website that looks exactly like the company's own authentication site (Twilio uses Okta, so this is easy to mock up). They enter their username and password, and the fake site forwards the entered credentials to the real site. If the real site then transitions to a 2FA prompt, the fake site will also do that. The victim then enters their 2FA code, the fake site forwards the 2FA code to the real site, and then is rewarded with a valid session cookie. The fake site can then even redirect to the real site so the victim doesn't realize they've been duped. The entire attack process includes testing the credentials as a necessary part of getting the 2FA code.
- mattbee 4y agoA reasonable (& previously common) defence against this was an IT-provided VPN setup, with a certificate. My old company didn't put employee endpoints on the public internet, so they couldn't be exploited without a working VPN connection. Asking victims to upload their VPN certificate isn't impossible, but raises the difficulty of the attack.
- kelnos 4y agoTwilio's VPN does use a certificate. I have no direct insider knowledge related to this specific incident, but I suspect the VPN wasn't breached. My guess is someone phished their way in through Okta SSO, and then was able to access something like Salesforce, or some other third-party hosted app that Twilio uses.
- kelnos 4y ago> Kudos to them for showing the kind of messages that caught their own employees out - though to me they seem jarring and unsophisticated. Agreed. A former colleague pointed out that company comms of this sort would never have exclamation marks in them. They don't look as amateurish as some of the poorly-spelled/poorly-punctuated/poor-grammar phishing attempts I've seen, but they don't look particularly legitimate to me either. But remember that, in a company of over 8,000 people, many of them very non-technical (tech companies are staffed by people of all levels of technical proficiency), all it takes is one or two or three people to fall for it. And maybe they were tired, or had a beer or two in them, or something like that.