Twilio put out an incident report today that I've had open in a tab since this morning, half-reading it between other things. Short version: someone sent a bunch of Twilio employees a text message pretending to be from IT, saying their password had expired or their schedule had changed, with a link to what looked like the company's Okta login page. Some employees typed in their real credentials. Whoever was behind it used those to get into internal systems and pull customer contact info and authentication data for something like 163 customers. Not a huge number in the grand scheme, but Twilio runs the plumbing behind a lot of apps you'd recognize, so "163 customers" doesn't mean 163 people.
What gets me isn't the sophistication, because there isn't any. This wasn't some zero-day. It was a text message. Somebody typed out a fake IT message, bought a domain that looked close enough, and waited. That's it. And it worked on a security company, on people whose whole job is thinking about this stuff. I don't say that to dunk on Twilio's employees. I'd probably fall for a good one too, especially at 8am before coffee, thumbing through notifications half asleep. That's kind of the point though. The attack doesn't need to be clever if it just needs one tired person on one bad morning.
I get these texts too, constantly
I've been getting a steady drip of fake delivery texts for weeks now: "your package has a delivery exception, confirm your address," with a link, from a number that's obviously not USPS or UPS or whoever they're pretending to be. I don't click them, but I'll admit the first one I got, back in June, I almost did, because I actually was expecting a package that week. That's the whole trick. It's not about fooling everyone. It's about fooling the handful of people for whom the message happens to be plausible on that particular day.
The part of the Twilio thing that actually changed how I think about my own accounts is realizing how much of my "security" still runs on SMS. I moved most of my important logins to an authenticator app years ago, or so I thought, and then went digging through old account settings this afternoon and found at least three services, one of them a bank, still set to text me a six digit code as the only second factor. No app option, or I set it up once and quietly let it lapse back to SMS without noticing. SMS codes get intercepted, SIM-swapped, or in cases like this, made irrelevant entirely because the attacker just walks in the front door with a stolen password and doesn't need your phone at all.
I use Authy for a lot of my 2FA, which is a Twilio product, which made reading their incident report a little more personal than it probably needed to be. Nothing in the report suggests Authy user accounts were touched, to be clear; this was about their internal employee access and a set of enterprise customers, not the consumer app. But it's a good reminder that "the company that makes my security tool" and "a company that can get phished" are not mutually exclusive categories. Nobody's exempt just because security is in their product description.
Black Hat is happening in Vegas this week too, which made the timing almost funny in a bleak way — a huge chunk of the security industry sitting in Mandalay Bay conference rooms talking about advanced threat detection while one of the more consequential breaches of the month came down to a text message and a bored Tuesday. I'm not saying the fancy stuff doesn't matter. I'm saying the boring stuff is still what gets people, over and over, and it's cheap enough that it'll keep working until phishing-resistant login (the physical key kind, not the app-based codes) is the default instead of the thing you have to go dig through settings to turn on.
Going to spend part of the weekend actually auditing which of my accounts still fall back to text codes and switching the ones I can over to a hardware key. Probably should've done this after the last one of these stories too. There's always a last one of these stories.