{
  "type": "bundle",
  "id": "bundle--ef3f2d47-3629-538e-80f6-8ce9966a025f",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--38b0ead1-dbd3-52ab-88eb-fac3e05a0612",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "org:db6eaee5-4c60-529e-8610-c378548e6ba8",
      "name": "Twilio",
      "identity_class": "organization"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--6e58397d-f79b-5099-8b82-16a6de9d35b9",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "inc:0c8c14a3-e02e-5f11-9f1c-85511671487c",
      "name": "Twilio security incident"
    },
    {
      "type": "incident",
      "spec_version": "2.1",
      "id": "incident--fec7e59d-bad5-5476-8492-1188df8ff574",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "brh:8619e96e-f03b-5305-afa3-9e07624298c7",
      "name": "Twilio security incident"
    },
    {
      "type": "relationship",
      "spec_version": "2.1",
      "id": "relationship--a24d3d4c-1e64-5a78-8673-2d2fd32baa7e",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:45bfc09d-2f86-5b31-bf73-98975a2022d2",
      "relationship_type": "affected-organization",
      "source_ref": "incident--6e58397d-f79b-5099-8b82-16a6de9d35b9",
      "target_ref": "identity--38b0ead1-dbd3-52ab-88eb-fac3e05a0612",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Twilio",
          "url": "https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack",
          "external_id": "cit:c5d31afc-fe12-5dcb-83a2-ba478a7ee52a",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:0119b9b8629ed857322390933b6e6206f3a1f912d5ca0b2996b8747cd1944f0b"
        }
      ]
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--19e773c4-65bf-506f-82d8-f2a54f409c7f",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:ce89ef08-696f-5205-a6d6-15da0d9fe8be",
      "confidence": 91,
      "external_references": [
        {
          "source_name": "Twilio",
          "url": "https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack",
          "external_id": "cit:baca2c8d-13af-5d65-b726-a7a6f9e141ea",
          "description": "According to these researchers – who have dubbed the malicious actors “0ktapus” or “Scatter Swine” – the attacks involved (a) identifying the mobile phone numbers of employees at such organizations, (b) sending smishing texts or making voice phishing (“vishing”) phone calls to identified phone numbers to trick the employees into clicking on links that led to fake Okta, Azure, Duo and other login pages, (c) harvesting the employees’ credentials and one-time passwords (“OTPs”) through those fake pages, and (d) using those credentials to advance reconnaissance operations within the target networks in order to attempt user account takeovers and further smishing efforts targeting other organizations.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:0119b9b8629ed857322390933b6e6206f3a1f912d5ca0b2996b8747cd1944f0b"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "0ktapus phishing kit; SMS phishing of employees for Okta credentials."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--483b69a4-f185-5e1f-88bd-f6e18b3a725c",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:a60dd6ac-cea5-53bf-b334-c9ee47f4ed00",
      "confidence": 95,
      "external_references": [
        {
          "source_name": "Twilio",
          "url": "https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack",
          "external_id": "cit:67eda07e-96a9-5e1e-a218-704fef7a9543",
          "description": "- We have identified approximately 125 Twilio customers whose data was accessed by malicious actors for a limited period of time, and we have notified all of them - There is no evidence that customer passwords, authentication tokens, or API keys were accessed without authorization",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:0119b9b8629ed857322390933b6e6206f3a1f912d5ca0b2996b8747cd1944f0b"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "Customer data accessed."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--6fbbf089-e86f-593a-8f7a-c12301ffbfcf",
      "created": "2026-09-18T12:00:00Z",
      "modified": "2026-09-18T12:00:00Z",
      "x_ally_original_id": "clm:c4d8a9ae-04a9-5f46-b434-1ea112164c2b",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Twilio",
          "url": "https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack",
          "external_id": "cit:fb5fd80e-bba6-56b7-a66e-59f10b96e747",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:0119b9b8629ed857322390933b6e6206f3a1f912d5ca0b2996b8747cd1944f0b"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The reviewed source documents the twilio security incident involving Twilio."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--70715598-0a48-5822-8430-0f543034521f",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:84d9ad34-fd0c-50fd-af59-447ff623c419",
      "confidence": 100,
      "external_references": [
        {
          "source_name": "Twilio",
          "url": "https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack",
          "external_id": "cit:3836d408-dd2f-572e-8897-ff226252f993",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:0119b9b8629ed857322390933b6e6206f3a1f912d5ca0b2996b8747cd1944f0b"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "date",
        "value": "2022-10-27"
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--b569a24e-01ef-5ba9-8aa5-995c545ef614",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:55eddb0f-8d83-580d-b2ad-9ab96bdcdaaa",
      "confidence": 90,
      "external_references": [
        {
          "source_name": "Twilio",
          "url": "https://www.twilio.com/en-us/blog/august-2022-social-engineering-attack",
          "external_id": "cit:4bfd5c2e-d826-5af0-975c-9107f6975486",
          "description": "We have heard from other companies that they, too, were subject to similar attacks, and have coordinated our response to the threat actors – including collaborating with carriers to stop the malicious messages, as well as their registrars and hosting providers to shut down the malicious URLs.",
          "x_ally_stance": "supports",
          "x_ally_snapshot_id": "snp:sha256:0119b9b8629ed857322390933b6e6206f3a1f912d5ca0b2996b8747cd1944f0b"
        }
      ],
      "x_ally_claim_object": {
        "kind": "value",
        "datatype": "string",
        "value": "The retained source describes containment action intended to limit further access or disruption."
      }
    },
    {
      "type": "x-ally-claim",
      "spec_version": "2.1",
      "id": "x-ally-claim--ea4017c8-d5b7-55eb-8dfa-cb9f13fcbbb1",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "clm:e79509d8-e8e8-5d52-88fe-fffd4517962e",
      "confidence": 90,
      "external_references": [],
      "x_ally_claim_object": {
        "kind": "iri",
        "value": "https://attack.mitre.org/techniques/T1566/"
      }
    },
    {
      "type": "x-ally-event",
      "spec_version": "2.1",
      "id": "x-ally-event--b40f111e-ba21-520d-8001-a052130b76b7",
      "created": "2026-09-19T12:00:00Z",
      "modified": "2026-09-19T12:00:00Z",
      "x_ally_original_id": "evt:b0aed61c-10a2-544b-a803-f86cdd4a08e2",
      "name": "Documented public update"
    }
  ]
}
