💣🔗
Twilio Security Incident
Summer 2022
1096 days ago
Resolved
Incident Overview
Situation Description
A 19-year-old Florida man was arrested and charged with wire fraud, identity theft, and SIM-swapping to steal cryptocurrency, linked to a hacking group responsible for cyber intrusions at major U.S. technology companies in the summer of 2022.
Event Types
Malware / Destructive Attack
Supply Chain Compromise
Industry Sector
TechnologyGeographic Scope
National (US)Response Actions
Notified Affected Individuals & Entities
Fulfilled Formal Breach Disclosure Obligations
Impact Analysis
Event Types (2 identified)
Malware / Destructive Attack
Supply Chain Compromise
Financial Impact
$800,000 USDRecords Affected
0Data Types Compromised
PII (Personally Identifiable Information)
Credentials
Source Code
Operational / System Data
Primary Impacts
Financial Loss
Data Exposure
Operational Disruption
Reputational Damage
Key Decisions Made
Twilio disclosed in Aug. 2022 that an intrusion had exposed a limited number of Twilio customer accounts through a sophisticated social engineering attack designed to steal employee credentials.; LastPass disclosed on November 30, 2022 a far more serious breach that the company said leveraged data stolen in the August breach, where criminal hackers had stolen encrypted copies of some password vaults, as well as other personal information.; On August 24, 2022, Plex's security team urged users to reset their passwords, saying an intruder had accessed customer emails, usernames and encrypted passwords.
Technical Analysis
Attack Method
Social Engineering
Threat Actor Attribution
Scattered Spider
0ktapus
Star Fraud
Vulnerability / Tool
Plex Media Server (unpatched)
Additional Information
Quick Facts
- Company:
- Twilio
- Date:
- Summer 2022
- Status:
- Resolved
- Decision Maker:
- nan
- Position:
- nan
- Published:
- 9/01/2024
Source Information
Original Query
DOJ indictments against Scattered Spider or UNC3944 membersTimeline
Information Published
9/01/2024
Incident Occurred
Summer 2022 (1096 days ago)
Status: Resolved
Estimated resolution based on age