• Daily Illinois
  • About
  • Contact
  • Privacy
  • Terms
  • DMCA
  • Sitemap
  • Write For Us
Daily illinois - USA | News, Sports & Updates Web Magazine
  • News
    • All
    • Business
    • Education
    • Politics
    • Sports
    • World
    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Lifesaving Domestic Violence Resources in Pinellas County

    Lifesaving Domestic Violence Resources in Pinellas County

    Non-Cash Compensations to Keep Employees Motivated!

    4 Powerful Non-Cash Compensations to Keep Employees Motivated!

    Brand Awareness Measurement Strategies

    8 Proven Brand Awareness Measurement Strategies to Grow

    Eco-Friendly Bubble Mailers: Boost Green Brand Reputation

    Eco-Friendly Bubble Mailers: Elevate Your Green Brand Reputation

    Unlock Faster App Development with Automation Testing

    Unlock Automation Testing to Master Faster App Development

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Highlights of AFC Asian Cup Qatar

    Highlights of AFC Asian Cup Qatar 2023

    Illinois sets a new record for cannabis sales. Doctors notice an increase in psychotic disorders due to the use of cannabis

    Illinois Sets a New Record for Cannabis Sales. Doctors Notice an Increase in Psychotic Disorders Due to the Use of Cannabis

  • Science & Tech
    • All
    • Ai - Artificial Intelligence
    • Apps
    • Mobile
    Having-trouble-with-AirDrop-Discover-ways-to-resolve-the-issue

    Having trouble with AirDrop? Discover ways to resolve the issue.

    MiniTool ShadowMaker Best Backup Software for Your Data

    MiniTool ShadowMaker Best Backup Software for Your Data

    What exactly is a Snapchat Streak

    What exactly is a Snapchat Streak?

    Access WhatsApp on your iPad through WhatsApp Web.

    Ways to Access WhatsApp on an iPad

    AI and Machine Learning Trends Revolutionizing Security

    7 AI and Machine Learning Trends Revolutionizing Security

    How-to-Lock-Your-Facebook-Profile-on-iPhone,-Android-&-Desktop

    How to Lock Your Facebook Profile on iPhone, Android & Desktop

    How to Log out of Facebook

    Steps to Sign Out of Facebook

    How to Know If Someone Blocked You on Snapchat

    How to Know If Someone Blocked You on Snapchat

    How to Update Apps on iPhone (2024 Guide)

    How to Update Apps on iPhone

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Castle

    10 Awesome Projects to Create in Minecraft

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft.png

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    How Immersive Gaming & VR are Shaping PC Gaming's Future

    How Immersive Gaming & VR are Shaping PC Gaming’s Future

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Dance Studios in to Get Cheap Dance Classes in Chicago

    9 Dance Studios in to Get Cheap Dance Classes in Chicago

    Video Game

    Video Game Workers Must Continue to Join Unions in 2024

    Exploring the Free Best Websites Online Games

    Exploring the Free Best Websites Online Games

    • F95zone
  • Lifestyle
    • All
    • Fashion
    • Food
    • Travel
    Top Caption Selfie Hacks to Boost Your Engagement Fast!

    10 Best Caption Selfie Hacks to Boost Your Engagement Fast!

    Understanding Ear Wax Build-Up With Causes & Solutions

    Top 5 Ways to Prevent Ear Wax Build-Up Naturally

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To.jpg

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To

    Tips for Choosing Furniture: Creating a Space that Reflects You

    Tips for Choosing Furniture: Creating a Space that Reflects You

    5 Ways Pool Liners Boost Energy Efficiency

    Save Money: 5 Ways Pool Liners Boost Energy Efficiency

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Fat Reduction Treatments to Sculpt Your Dream Body!

    2 Best Fat Reduction Treatments to Sculpt Your Dream Body!

    Proven Steps to Get Rid of Lice Fast at a Lice Salon

    6 Powerful Reasons to Visit a Lice Salon for Fast Relief

    Reasons a Golf Ball Bottle Opener Will Be the Life of Your Next Party

    5 Reasons a Golf Ball Bottle Opener Will Elevate Your Party

    10 Steps to Your Perfect Senior Living Rentals Home!

    10 Steps to Your Perfect Senior Living Rentals Home!

  • Articles
    • Startup
    • Social Media
33 °f
Chicago
35 ° Sat
35 ° Sun
35 ° Mon
37 ° Tue
No Result
View All Result
Daily illinois - USA | News, Sports & Updates Web Magazine
  • News
    • All
    • Business
    • Education
    • Politics
    • Sports
    • World
    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Choosing the Right Construction Estimator: A Guide to Making the Best Decision

    Lifesaving Domestic Violence Resources in Pinellas County

    Lifesaving Domestic Violence Resources in Pinellas County

    Non-Cash Compensations to Keep Employees Motivated!

    4 Powerful Non-Cash Compensations to Keep Employees Motivated!

    Brand Awareness Measurement Strategies

    8 Proven Brand Awareness Measurement Strategies to Grow

    Eco-Friendly Bubble Mailers: Boost Green Brand Reputation

    Eco-Friendly Bubble Mailers: Elevate Your Green Brand Reputation

    Unlock Faster App Development with Automation Testing

    Unlock Automation Testing to Master Faster App Development

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Why Hiring a Custom Graphic Design Company is Key for Brand Success

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Giannis Antetokounmpo’s Performance: Greece Exits 2024 Olympics

    Highlights of AFC Asian Cup Qatar

    Highlights of AFC Asian Cup Qatar 2023

    Illinois sets a new record for cannabis sales. Doctors notice an increase in psychotic disorders due to the use of cannabis

    Illinois Sets a New Record for Cannabis Sales. Doctors Notice an Increase in Psychotic Disorders Due to the Use of Cannabis

  • Science & Tech
    • All
    • Ai - Artificial Intelligence
    • Apps
    • Mobile
    Having-trouble-with-AirDrop-Discover-ways-to-resolve-the-issue

    Having trouble with AirDrop? Discover ways to resolve the issue.

    MiniTool ShadowMaker Best Backup Software for Your Data

    MiniTool ShadowMaker Best Backup Software for Your Data

    What exactly is a Snapchat Streak

    What exactly is a Snapchat Streak?

    Access WhatsApp on your iPad through WhatsApp Web.

    Ways to Access WhatsApp on an iPad

    AI and Machine Learning Trends Revolutionizing Security

    7 AI and Machine Learning Trends Revolutionizing Security

    How-to-Lock-Your-Facebook-Profile-on-iPhone,-Android-&-Desktop

    How to Lock Your Facebook Profile on iPhone, Android & Desktop

    How to Log out of Facebook

    Steps to Sign Out of Facebook

    How to Know If Someone Blocked You on Snapchat

    How to Know If Someone Blocked You on Snapchat

    How to Update Apps on iPhone (2024 Guide)

    How to Update Apps on iPhone

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

  • Entertainment
    • All
    • Gaming
    • Movie
    • Music
    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of

    Castle

    10 Awesome Projects to Create in Minecraft

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft.png

    A Guide to Acquiring and Utilizing Command Blocks in Minecraft

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    Shooting Games Unblocked: A Comprehensive Guide to TBG95

    How Immersive Gaming & VR are Shaping PC Gaming's Future

    How Immersive Gaming & VR are Shaping PC Gaming’s Future

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Best Game Engines for Android and iOS For Simplifying Game Development in 2025

    Dance Studios in to Get Cheap Dance Classes in Chicago

    9 Dance Studios in to Get Cheap Dance Classes in Chicago

    Video Game

    Video Game Workers Must Continue to Join Unions in 2024

    Exploring the Free Best Websites Online Games

    Exploring the Free Best Websites Online Games

    • F95zone
  • Lifestyle
    • All
    • Fashion
    • Food
    • Travel
    Top Caption Selfie Hacks to Boost Your Engagement Fast!

    10 Best Caption Selfie Hacks to Boost Your Engagement Fast!

    Understanding Ear Wax Build-Up With Causes & Solutions

    Top 5 Ways to Prevent Ear Wax Build-Up Naturally

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To.jpg

    Driving Uninsured Here Are 5 Risks You’re Subjecting Yourself To

    Tips for Choosing Furniture: Creating a Space that Reflects You

    Tips for Choosing Furniture: Creating a Space that Reflects You

    5 Ways Pool Liners Boost Energy Efficiency

    Save Money: 5 Ways Pool Liners Boost Energy Efficiency

    Brazilian Jiu-Jitsu (BJJ) - 7 Proven Tips to Boost Your Skills

    Brazilian Jiu-Jitsu (BJJ) – 7 Proven Tips to Boost Your Skills

    Best Fat Reduction Treatments to Sculpt Your Dream Body!

    2 Best Fat Reduction Treatments to Sculpt Your Dream Body!

    Proven Steps to Get Rid of Lice Fast at a Lice Salon

    6 Powerful Reasons to Visit a Lice Salon for Fast Relief

    Reasons a Golf Ball Bottle Opener Will Be the Life of Your Next Party

    5 Reasons a Golf Ball Bottle Opener Will Elevate Your Party

    10 Steps to Your Perfect Senior Living Rentals Home!

    10 Steps to Your Perfect Senior Living Rentals Home!

  • Articles
    • Startup
    • Social Media
No Result
View All Result
Daily illinois - USA | News, Sports & Updates Web Magazine
No Result
View All Result
Home Science & Tech

Phishers who breached Twilio and fooled Cloudflare could easily get you, too

by admin
December 5, 2022
in Science & Tech
0
Phishers who breached Twilio and fooled Cloudflare could easily get you, too
495
SHARES
1.4k
VIEWS
Share on FacebookShare on Twitter

At least two security-sensitive companies—Twilio and Cloudflare—were targeted in a phishing attack by an advanced threat actor who had possession of home phone numbers of not just employees but employees’ family members as well.

In the case of Twilio, a San Francisco-based provider of two-factor authentication and communication services, the unknown hackers succeeded in phishing the credentials of an undisclosed number of employees and, from there, gained unauthorized access to the company’s internal systems, the company said. The threat actor then used that access to data in an undisclosed number of customer accounts.

Two days after Twilio’s disclosure, content delivery network Cloudflare, also headquartered in San Francisco, revealed it had also been targeted in a similar manner. Cloudflare said that three of its employees fell for the phishing scam, but that the company’s use of hardware-based MFA keys prevented the would-be intruders from accessing its internal network.

Well-organized, sophisticated, methodical

In both cases, the attackers somehow obtained the home and work phone numbers of both employees and, in some cases, their family members. The attackers then sent text messages that were disguised to appear as official company communications. The messages made false claims such as a change in an employee’s schedule, or the password they used to log in to their work account had changed. Once an employee entered credentials into the fake site, it initiated the download of a phishing payload that, when clicked, installed remote desktop software from AnyDesk.

RelatedPosts

Having-trouble-with-AirDrop-Discover-ways-to-resolve-the-issue

Having trouble with AirDrop? Discover ways to resolve the issue.

January 21, 2025
MiniTool ShadowMaker Best Backup Software for Your Data

MiniTool ShadowMaker Best Backup Software for Your Data

January 18, 2025
What exactly is a Snapchat Streak

What exactly is a Snapchat Streak?

December 27, 2024
Access WhatsApp on your iPad through WhatsApp Web.

Ways to Access WhatsApp on an iPad

December 26, 2024

Cloudflare

Twilio

The threat actor carried out its attack with almost surgical precision. When the attacks on Cloudflare, at least 76 employees received a message in the first minute. The messages came from a variety of phone numbers belonging to T-Mobile. The domain used in the attack had been registered only 40 minutes prior, thwarting the domain protection Cloudflare uses to ferret out impostor sites.

Advertisement

“Based on these factors, we have reason to believe the threat actors are well-organized, sophisticated, and methodical in their actions,” Twilio wrote. “We have not yet identified the specific threat actors at work here, but have liaised with law enforcement in our efforts. Socially engineered attacks are—by their very nature—complex, advanced, and built to challenge even the most advanced defenses.”

Matthew Prince, Daniel Stinson-Diess, Sourov Zaman—Cloudflare’s CEO, senior security engineer and incident response leader respectively—had a similar take.

“This was a sophisticated attack targeting employees and systems in such a way that we believe most organizations would be likely to be breached,” they wrote. “Given that the attacker is targeting multiple organizations, we wanted to share here a rundown of exactly what we saw in order to help other companies recognize and mitigate this attack.”

Twilio and Cloudflare said they don’t know how the phishers obtained employee numbers.

It’s impressive that despite three of its employees falling for the scam, Cloudflare kept its systems from being breached. The company’s use of hardware-based security keys that comply with the FIDO2 standard for MFA was a critical reason. Had the company relied on one-time passwords from sent text messages or even generated by an authentication app, it likely would have been a different story.

The Cloudflare officials explained:

When the phishing page was completed by a victim, the credentials were immediately relayed to the attacker via the messaging service Telegram. This real-time relay was important because the phishing page would also prompt for a Time-based One Time Password (TOTP) code.

Presumably, the attacker would receive the credentials in real-time, enter them in a victim company’s actual login page, and, for many organizations that would generate a code sent to the employee via SMS or displayed on a password generator. The employee would then enter the TOTP code on the phishing site, and it too would be relayed to the attacker. The attacker could then, before the TOTP code expired, use it to access the company’s actual login page — defeating most two-factor authentication implementations.

Cloudflare

We confirmed that three Cloudflare employees fell for the phishing message and entered their credentials. However, Cloudflare does not use TOTP codes. Instead, every employee at the company is issued a FIDO2-compliant security key from a vendor like YubiKey. Since the hard keys are tied to users and implement origin binding, even a sophisticated, real-time phishing operation like this cannot gather the information necessary to log in to any of our systems. While the attacker attempted to log in to our systems with the compromised username and password credentials, they could not get past the hard key requirement.

Cloudflare went on to say it wasn’t disciplining the employees who fell for the scam and explained why.

Advertisement

“Having a paranoid but blame-free culture is critical for security,” the officials wrote. “The three employees who fell for the phishing scam were not reprimanded. We’re all human and we make mistakes. It’s critically important that when we do, we report them and don’t cover them up.”

Source by arstechnica.com

Related

Related Posts

AI and Machine Learning Trends Revolutionizing Security

7 AI and Machine Learning Trends Revolutionizing Security

December 4, 2024
Real innovations only in the iphone Pro model

Buy iPhone 14 or 14 Pro? Real innovations only in the Pro model

December 6, 2022
Upgraded Your iPhone to iOS 16? Take These 3 Steps Immediately

Upgraded Your iPhone to iOS 16? Take These 3 Steps Immediately

October 18, 2024
How to Select Residential Solar Installers: What You Need to Know

How to Select Residential Solar Installers: What You Need to Know

December 27, 2021

Trending

  • How to Clone NVMe to NVMe SSD Without Reinstalling
  • Comprehensive Guide to Among Us Characters Everything You Should Be Aware Of
  • Having trouble with AirDrop? Discover ways to resolve the issue.
  • 10 Awesome Projects to Create in Minecraft
  • A Guide to Acquiring and Utilizing Command Blocks in Minecraft
  • MiniTool ShadowMaker Best Backup Software for Your Data
  • 10 Best Caption Selfie Hacks to Boost Your Engagement Fast!
Daily illinois

© 2025 Dailyillinos.com

Navigate Site

  • Daily Illinois
  • About
  • Contact
  • Privacy
  • Terms
  • DMCA
  • Sitemap
  • Write For Us

Follow Us

No Result
View All Result
  • About Us Page
  • Contact
  • Daily illinois
  • DMCA Policy
  • Privacy Policy
  • Submit, Guest Post, Write For Us and Become a Contributor
  • Terms of Use

© 2025 Dailyillinos.com

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.