Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencevoice-social-engineeringidentity-authentication-vulnerabilitycredential-access-method

Voice and SMS phishing campaigns abused Okta workflows to breach hundreds of firms

Updated 29d agoFirst seen May 25, 20269 sources

A series of social-engineering campaigns targeted organizations that relied on Okta and similar identity systems, using SMS phishing, fake login portals, and later voice calls impersonating IT staff to steal credentials, MFA codes, and session tokens. Group-IB said the 0ktapus operation targeted 136 organizations, used 169 lookalike domains, and compromised thousands of accounts, with victims concentrated in technology, software, and cloud sectors in the United States and Canada. Reporting tied the same activity to breaches at Twilio, Cloudflare, DoorDash, and later Coinbase, where an attacker obtained an employee username and password and accessed limited corporate directory data but was blocked from broader access by MFA controls and incident response.

Subsequent reporting described an evolution from SMS phishing to vishing and adversary-in-the-middle phishing kits that mirrored corporate SSO flows in real time, enabling theft of session tokens even after MFA was completed. Mandiant and other researchers linked a 2026 wave under the ShinyHunters banner to more than 400 organizations, with attackers using branded phishing sites, harvesting cloud data from SharePoint, OneDrive, Salesforce, and Slack, and following theft with extortion demands. Across the incidents, phishing-resistant FIDO2 security keys stood out as an effective defense, while earlier disputes over Okta-related intrusions, including claims by Lapsus$, underscored how compromises of identity providers and support channels can cascade into downstream customer exposure.

Share:
Voice and SMS phishing campaigns abused Okta workflows to breach hundreds of firms
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Mar 12, 20263mo ago

Researchers detail ShinyHunters campaign affecting 400+ organizations

On 2026-03-12, researchers published technical details on the ShinyHunters-linked campaign, including real-time phishing kits that captured session tokens after MFA and post-compromise theft from SharePoint, OneDrive, Salesforce, and Slack. The report named victims including Match Group, SoundCloud, Panera Bread, Betterment, Harvard, Crunchbase, Canada Goose, and Aura.

Mar 3, 20264mo ago

Optimizely disclosed as victim of suspected vishing attack

On 2026-03-03, reporting identified ad-tech firm Optimizely as a victim of a suspected ShinyHunters vishing attack that leaked business information. This added a named victim to the expanding campaign.

Jan 26, 20265mo ago

Public reporting documents ShinyHunters-style vishing wave

By late January 2026, public reporting described a cybercrime group claiming responsibility for voice-phishing attacks targeting Okta-linked environments. The reporting marked broader public awareness of the campaign's methods and actor claims.

Jan 9, 20266mo ago

Large-scale ShinyHunters-linked vishing campaign begins

In January 2026, a broad voice-phishing campaign began in which attackers impersonated IT support staff and sent employees to victim-branded credential harvesting sites. Mandiant later associated the activity with the ShinyHunters banner and said the campaign ultimately reached more than 400 organizations.

Feb 21, 20233y ago

Coinbase publicly details limited 0ktapus-related intrusion

On 2023-02-21, Coinbase disclosed that a persistent cybercriminal associated with 0ktapus had accessed its corporate directory through a combination of smishing and a follow-up phone call. Coinbase said its controls blocked remote access because the attacker failed MFA, and the incident affected only limited employee contact information.

Coinbase employee phished and socially engineered by 0ktapus actor

Before Coinbase's February 2023 disclosure, a threat actor linked to 0ktapus used SMS phishing to steal an employee's username and password, then followed up with a voice social-engineering call impersonating Coinbase IT. The attacker gained limited access to Coinbase's corporate directory, exposing employee contact details, but could not satisfy MFA requirements or access customer funds or customer information.

Aug 26, 20224y ago

Group-IB identifies 0ktapus targeting 136 organizations

On 2022-08-26, Group-IB publicly linked the actors behind the Twilio and Cloudflare incidents to a campaign dubbed 0ktapus that targeted 136 organizations. The firm said the operation used 169 phishing domains and resulted in 9,931 compromised accounts and 3,120 credentials with email addresses.

Aug 25, 20224y ago

Twilio and Cloudflare breaches linked to broader 0ktapus campaign

In August 2022, reporting tied the intrusions at Twilio and Cloudflare to the same threat actor behind the wider 0ktapus phishing campaign. The activity was described as a supply-chain style operation that leveraged data from one compromise to target downstream organizations.

Mar 23, 20224y ago

Lapsus$ posts Okta screenshots and Okta discloses January incident

On 2022-03-23, the extortion group Lapsus$ published screenshots claiming an Okta breach, prompting Okta to confirm the earlier January compromise of a third-party support engineer account. Okta said about 2.5% of customers were potentially impacted, while Lapsus$ disputed Okta's characterization and claimed broader access.

Jan 16, 20224y ago

Attacker accesses Okta support engineer laptop via third party

In January 2022, an attacker gained access for five days to a third-party customer support engineer's laptop used to support Okta customers. Okta later said the incident was contained and did not breach its core services, though support-related access was exposed.

Attackers prepare large vishing infrastructure for new campaign

In December 2025, attackers registered many of the domains later used in a large-scale vishing campaign, indicating advance preparation. Silent Push later identified more than 150 attacker-controlled domains tied to the operation.

0ktapus phishing campaign operates against Okta-using firms

By March 2022, the 0ktapus operation was active and reportedly remained undetected while targeting organizations that used Okta, primarily in IT, software development, and cloud services. The attackers used SMS phishing and fake Okta login pages to steal credentials and one-time codes.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.