A Tale of Two Phishes: Lessons From The Twilio and Cloudflare SMS Spear Phishing Attacks
ID: 9808e23e-50a9-5329-96ee-0677ab2c7c67
STIX ID: report--9808e23e-50a9-5329-96ee-0677ab2c7c67
Feed Name: Zimperium Blog
The report describes a coordinated SMS spear-phishing campaign that successfully compromised multiple Twilio employee credentials, leading to customer data exposure (~125 Twilio customers; Signal reported ~1,900 affected users), while a similar attack against Cloudflare was mitigated by FIDO2 physical security keys. Attackers used targeted social engineering (matching names to phone numbers, US-based numbers) and convincing phishing pages delivered via SMS; the document stresses that mobile endpoints remain a primary unprotected vector and recommends stronger mobile threat defense and hardware-backed authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
