• Latest
  • Trending
  • All
  • News
  • Business
  • Politics
  • Science
  • World
  • Lifestyle
  • Tech
A huge phishing campaign has targeted over 130 companies, affecting Twilio and Signal

A huge phishing campaign has targeted over 130 companies, affecting Twilio and Signal

August 26, 2022
‘Dear Edward’ and ‘Shrinking’: TV Really Wants Us to Cry About Therapy and Grief

‘Dear Edward’ and ‘Shrinking’: TV Really Wants Us to Cry About Therapy and Grief

February 4, 2023
Rutgers Men’s Basketball Turns the Garden Red for One Day

Rutgers Men’s Basketball Turns the Garden Red for One Day

February 4, 2023
Armie Hammer reveals childhood sexual abuse and suicide attempt as he speaks out on rape allegation

Armie Hammer reveals childhood sexual abuse and suicide attempt as he speaks out on rape allegation

February 4, 2023
Kate Middleton hires ‘ball-breaking’ aide to shake up Kensington Palace

Kate Middleton hires ‘ball-breaking’ aide to shake up Kensington Palace

February 4, 2023
Video Shows Chinese Balloon Being Shot Down Over Atlantic Ocean

Video Shows Chinese Balloon Being Shot Down Over Atlantic Ocean

February 4, 2023
Guy Fieri Lights Sally Field on Fire in Ridiculous ‘80 for Brady’

Guy Fieri Lights Sally Field on Fire in Ridiculous ‘80 for Brady’

February 4, 2023
Former Stable Girl Claims to Be the ‘Older’ Woman Who Took Prince Harry’s Virginity

Former Stable Girl Claims to Be the ‘Older’ Woman Who Took Prince Harry’s Virginity

February 4, 2023
Taylor Lautner Copped To Finding Jacob “Annoying” In ‘Twilight’

Taylor Lautner Copped To Finding Jacob “Annoying” In ‘Twilight’

February 4, 2023
Brutal Cold Seizes Northeast U.S., Shattering Record Lows

Brutal Cold Seizes Northeast U.S., Shattering Record Lows

February 4, 2023
Controversial former NBA player says Colin Kaepernick had ‘most freedom’ he ever felt after anthem protests

Controversial former NBA player says Colin Kaepernick had ‘most freedom’ he ever felt after anthem protests

February 4, 2023
Reese Witherspoon Says “There Is No ‘Legally Blonde 3’ Without Jennifer Coolidge”

Reese Witherspoon Says “There Is No ‘Legally Blonde 3’ Without Jennifer Coolidge”

February 4, 2023
Black fraternity Omega Psi Phi boots cops involved in Tyre Nichols’ death

Black fraternity Omega Psi Phi boots cops involved in Tyre Nichols’ death

February 4, 2023
DNYUZ
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Music
    • Movie
    • Television
    • Theater
    • Gaming
    • Sports
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel
No Result
View All Result
DNYUZ
No Result
View All Result
Home News

A huge phishing campaign has targeted over 130 companies, affecting Twilio and Signal

August 26, 2022
in News, Tech
A huge phishing campaign has targeted over 130 companies, affecting Twilio and Signal
511
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Over 130 organizations, including Twilio, DoorDash, and Cloudflare, have been potentially compromised by hackers as part of a months-long phishing campaign nicknamed “0ktapus” by security researchers. Login credentials belonging to nearly 10,000 individuals were stolen by attackers who imitated the popular single sign-on service Okta, according to a report from cybersecurity outfit Group-IB.

As Group-IB goes on to detail, the attackers used that access to pivot and attack accounts across other services. On August 15th, the secure messaging service Signal alerted users that the attackers’ Twilio breach allowed them to reveal as many as 1,900 Signal accounts and confirmed they were able to register new devices to the accounts of a few, which would allow the attackers to send and receive from that account. This week Twilio also updated its breach notification, noting that 163 customers had their data accessed. It also noted that 93 users of Authy, its cloud service for multifactor authentication, had their accounts accessed and additional devices registered.

Targets of the phishing campaign were sent text messages that redirected them to a phishing site. As the report from Group-IB states, “From the victim’s point of view, the phishing site looks quite convincing as it is very similar to the authentication page they are used to seeing.” Victims were asked for their username, password, and a two-factor authentication code. This information was then sent to the attackers.

Interestingly, Group-IB’s analysis suggests that the attackers were somewhat inexperienced. “The analysis of the phishing kit revealed that it was poorly configured and the way it had been developed provided an ability to extract stolen credentials for further analysis,” Roberto Martinez, a senior threat intelligence analyst at Group-IB, told TechCrunch.

But inexperienced or not, the scale of the attack is massive, with Group-IB detecting 169 unique domains targeted by the campaign. It’s believed that the 0ktapus campaign began around March 2022 and that so far, around 9,931 login credentials have been stolen. The attackers have spread their net wide, targeting multiple industries, including finance, gaming, and telecoms. Domains cited by Group-IB as targets (but not confirmed breaches) include Microsoft, Twitter, AT&T, Verizon Wireless, Coinbase, Best Buy, T-Mobile, Riot Games, and Epic Games.

Cash appears to be at least one of the motives for the attacks, with researchers stating, “Seeing financial companies in the compromised list gives us the idea that the attackers were also trying to steal money. Furthermore, some of the targeted companies provide access to crypto assets and markets, whereas others develop investment tools.”

Group-IB warns that we likely won’t know the full scale of this attack for some time. In order to guard against similar attacks like this, Group-IB offers the usual advice: always be sure to check the URL of any site where you’re entering login details; treat URLs received from unknown sources with suspicion; and for added protection, you can use an “unphishable” two-factor security keys, such as a YubiKey.

This recent string of phishing attacks is one of the most impressive campaigns of this scale to date, according to Group-IB, with the report concluding that “Oktapus shows how vulnerable modern organizations are to some basic social engineering attacks and how far-reaching the effects of such incidents can be for their partners and customers.”

The scale of these threats isn’t likely to decrease any time soon, either. Research from Zscaler shows that phishing attacks increased by 29 percent globally in 2021 compared to the previous year and notes that SMS phishing in particular is increasing faster than other kinds of scams as people have started to better recognize fraudulent emails. Socially engineered scams and hacks were also seen rising during the COVID-19 pandemic, and earlier this year, we even saw that both Apple and Meta shared data with hackers pretending to be law enforcement officials.

Correction August 26th, 2:26PM ET: An earlier version of this story included Signal as one of the companies targeted and compromised by the phishing attacks. It was not one of the victims with security breached by the attackers through phishing. The attackers breached Twilio, which handles text messaging for phone number verifications, and were able to register new devices to the accounts of Signal users without having access to Signal directly. We regret the error.

The post A huge phishing campaign has targeted over 130 companies, affecting Twilio and Signal appeared first on The Verge.

Tags: CybersecurityTech
Share204Tweet128Share

Trending Posts

Man Accused of Firing Blank Rounds Inside a Synagogue, Police Say

Man Accused of Firing Blank Rounds Inside a Synagogue, Police Say

February 4, 2023
Scientists to engineer woolly mammoth’s return by 2027

Scientists to engineer woolly mammoth’s return by 2027

February 4, 2023
Paul McCartney’s Decade-Long Creative Surge Post-Beatles To Be Explored In ‘Man On The Run’ From Oscar Winner Morgan Neville

Paul McCartney’s Decade-Long Creative Surge Post-Beatles To Be Explored In ‘Man On The Run’ From Oscar Winner Morgan Neville

February 4, 2023
East Palestine, Ohio, 50-car train derailment fire keeps burning

East Palestine, Ohio, 50-car train derailment fire keeps burning

February 4, 2023
Schools being renamed in campaign to remove ‘dead, white British guys’

Schools being renamed in campaign to remove ‘dead, white British guys’

February 4, 2023

Copyright © 2023.

Site Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

No Result
View All Result
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Gaming
    • Music
    • Movie
    • Sports
    • Television
    • Theater
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel

Copyright © 2023.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT