A single SMS-phishing campaign lured employees to fake Okta login pages, harvested ~9,931 credentials and 5,441 MFA codes across 136 organizations, and used the access to pivot into downstream supply-chain attacks.
Reviewed by the Social Engineering Examples team.
Beginning in at least March 2022, attackers ran a large-scale text-message (smishing) phishing campaign against employees of companies that use Okta for single sign-on. Employees received SMS messages impersonating their IT department, warning that a password had expired or a schedule had changed and linking to a lookalike Okta login page. Victims who entered their username, password, and MFA/one-time code delivered them to the attackers. Group-IB, which uncovered the operation while investigating an incident for a client, codenamed it "0ktapus" and detected 169 unique phishing domains. Group-IB's analysis of the attackers' data showed roughly 9,931 stolen user credentials (about 3,120 with corporate emails and 6,811 without) and 5,441 captured MFA codes, spanning 136 identified victim organizations, most of them U.S.-based IT, software, and cloud companies. Confirmed breaches included Twilio (detected Aug 4, 2022; ultimately 163 customers and 93 Authy accounts affected) and Mailchimp and Klaviyo; Cloudflare was targeted on July 20, 2022, when 76 employees were texted and three entered credentials, but hardware security keys prevented any compromise. The stolen access was used to launch downstream supply-chain attacks: Twilio access exposed data enabling re-registration attempts on ~1,900 Signal accounts, and a Mailchimp compromise touched DigitalOcean's transactional email.
The campaign paired smishing with a real-time adversary-in-the-middle relay. Attackers registered domains containing keywords like "okta," "sso," "vpn," "mfa," and "help" plus the target's brand, and cloned the organization's exact Okta login page so it looked identical to what employees expected. SMS was chosen because texts feel personal and urgent and bypass email security gateways; messages spoofed the internal IT team and used time pressure. Crucially, when a victim submitted credentials, the phishing kit relayed them instantly to the attackers (via a Telegram channel), who entered them into the real login portal; the fake page then prompted for the one-time MFA code, which was likewise relayed and used before it expired, defeating SMS/TOTP-based MFA. In some flows the page also pushed AnyDesk remote-access software. It worked because the lures exploited routine IT-driven behavior, the pages were pixel-accurate, freshly registered domains evaded brand-monitoring detection (Cloudflare's spoofed domain was registered under 40 minutes before the blast), and phishable one-time codes gave a false sense of protection.
Lure: a text message appearing to come from your company's IT/help desk saying your password expired or your work schedule changed, with a link to an "Okta"/"SSO" login page. Tells: the message arrives by SMS (legitimate IT rarely texts urgent login links), it creates time pressure, and the link goes to a domain that only looks official (e.g., brand-okta.com, brand-sso.net) rather than your real Okta/SSO URL. Any page asking you to re-enter both your password and your MFA code after clicking an unsolicited link is a red flag.
Group-IB publicly disclosed the campaign on August 25, 2022, linking the Twilio and Cloudflare incidents to one operation and publishing infrastructure indicators. Twilio revoked compromised accounts, engaged forensics, notified 163 affected customers and 93 Authy users, and worked with carriers, registrars, and hosting providers to take down infrastructure. Cloudflare was not breached because FIDO2 hardware keys with origin binding blocked the attackers even after credentials were phished. The episode became a landmark case for why SMS/TOTP MFA is phishable and why phishing-resistant hardware keys matter.
0ktapus showed that low-sophistication tooling (a simple phishing kit plus SMS) could compromise well-known, security-mature companies at scale by defeating MFA through real-time relay of one-time codes. It demonstrated the supply-chain blast radius of identity compromise: breaching one vendor (Twilio, Mailchimp) opened paths into their customers (Signal, DigitalOcean). The clearest lesson is that not all MFA is equal. Cloudflare's phishing-resistant FIDO2 keys stopped the exact attack that breached peers relying on push/OTP codes.
Deploy phishing-resistant MFA (FIDO2/WebAuthn hardware security keys with origin binding) instead of SMS or TOTP one-time codes. Train employees that IT will not text urgent login links, and give an easy way to report suspicious messages. Verify the exact SSO/Okta domain before entering credentials, and treat links from unknown sources as suspicious. Use secure web gateways / DNS filtering to block newly registered and lookalike domains, and monitor for brand-impersonation domain registrations. Enforce endpoint controls that block unsanctioned remote-access tools (e.g., AnyDesk). Rotate credentials and terminate active sessions immediately on suspected compromise, and require MFA re-enrollment.
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
Attackers hijacked the New Haven school COO's email, quietly monitored a real $5.9M bus-contract payment thread, spoofed the vendor to…