Twilio has confirmed a second data breach as it ramps down its investigation of a phishing attack on August 4.
The newly revealed attack occurred on June 29, 2022, when a Twilio employee fell victim to a voice phishing – otherwise known as "vishing" – scam.
After, the hacker gained access to the contact information of a "limited number of customers."
Giving more details in an incident report for the already publicized attack, Twilio states:
The threat actor’s access was identified and eradicated within 12 hours. Customers whose information was impacted by the June Incident were notified on July 2, 2022.
Some will question why Twilio did not immediately make the news public, as it did for the data breach on August 4.
Indeed, it was clear in its response to that attack, stating what happened, what they have done, and providing next steps – providing a real sense of transparency.
Yet, burying news of this "brief security incident" at the bottom of the incident report for another attack seems somewhat murkier.
With that said, the attacks are connected, as Twilio reveals that the same actors likely performed both breaches.
Twilio's August Data Breach: Worse Than First Feared
When news of the August 4 phishing attack broke, reports suggested that approximately 125 customers had been affected.
However, the latest entry into Twilio's incident report suggests that the incident impacted 209 customers and 93 Authy end users.
Moreover, the attacks lasted until August 9, when the last observed unauthorized activity in Twilio's environment occurred.
Of course, these findings are troubling. Fortunately, Twilio confirms:
There is no evidence that the malicious actors accessed Twilio customers’ console account credentials, authentication tokens, or API keys.
Also, as Twilio boasts a total customer base of over 270,000, the attack only affected a fraction of its clients, thankfully.

