Socially engineered attacks are-by their very nature-complex, advanced, and built to challenge even the most advanced defenses." "We have not yet identified the specific threat actors at work here, but have liaised with law enforcement in our efforts. "Based on these factors, we have reason to believe the threat actors are well-organized, sophisticated, and methodical in their actions," Twilio wrote. Once an employee entered credentials into the fake site, it initiated the download of a phishing payload that, when clicked, installed remote desktop software from AnyDesk. The messages made false claims such as a change in an employee's schedule, or the password they used to log in to their work account had changed. The attackers then sent text messages that were disguised to appear as official company communications. In both cases, the attackers somehow obtained the home and work phone numbers of both employees and, in some cases, their family members. Well-organized, sophisticated, methodical Cloudflare said that three of its employees fell for the phishing scam, but that the company's use of hardware-based MFA keys prevented the would-be intruders from accessing its internal network. Two days after Twilio's disclosure, content delivery network Cloudflare, also headquartered in San Francisco, revealed it had also been targeted in a similar manner. The threat actor then used that access to data in an undisclosed number of customer accounts. In the case of Twilio, a San Francisco-based provider of two-factor authentication and communication services, the unknown hackers succeeded in phishing the credentials of an undisclosed number of employees and, from there, gained unauthorized access to the company's internal systems, the company said. At least two security-sensitive companies-Twilio and Cloudflare-were targeted in a phishing attack by an advanced threat actor who had possession of home phone numbers of not just employees but employees' family members as well.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |