Twilio Data Breach Happened Via Employee Smishing

Twilio is the Cloud Communications Company. They are the latest to fall victim to a data breach.

The company recently disclosed that some of its customer data was accessed by unknown attackers who gained access to the system by stealing employee login credentials via an SMS phishing attack, known as ‘Smishing,’ for short.

The company’s disclosure reads in part as follows:

“On August 4, 2022, Twilio became aware of unauthorized access to information related to a limited number of Twilio customer accounts through a sophisticated social engineering attack designed to steal employee credentials.

The attackers then used the stolen credentials to gain access to some of our internal systems, where they were able to access certain customer data.”

The smishing attack succeeded because the attackers were able to convince company employees that the SMS messages they were receiving were coming from the company’s own IT department.  The messages contained URLs containing the keywords “Twilio,” “SSO” and “Okta” which are commonly used by the company.

Unfortunately, if an employee tapped these links, they would not be taken to company resources but rather to a page that had been cloned to appear as a legitimate company sign in page.

Here, they received a message that their password had expired, and the employee was asked to enter their information as part of the process of changing it.

Naturally, this action did not change the employee’s password, but it did hand it over to the hackers waiting on the other end.

Per a Twilio spokesman, the attackers were only able to access data belonging to a limited number of customers, and the company is currently in the process of reaching out to those who were impacted.

If you have a Twilio account and are not contacted, your data and your account should be fine.  If you are contacted, Twilio will provide you with additional information at that time.

Malware Is Targeting Small Office And Home Office Routers

Researchers at Lumen’s Black Lotus Labs recently spotted evidence of a highly sophisticated and tightly targeted campaign aimed at SOHO (small office/home office) routers across both Europe and North America.

Based on the evidence the team has collected thus far, their conclusion is that the unidentified actor must be state sponsored. This is because garden variety hackers do not typically have the tools, techniques, and procedures in place to pull off the kinds of attacks that the researchers are seeing.

It is telling that this campaign’s ramp up coincided with the pandemic-fueled shift to large numbers of employees working from home.

A recently published summary report about the campaign reads in part, as follows:

“This (the massive surge in people working from home) gave threat actors a fresh opportunity to leverage at-home devices such as SOHO routers – which are widely used but rarely monitored or patched – to collect data in transit, hijack connections, and compromise devices in adjacent networks.

The sudden shift to remote work spurred by the pandemic allowed a sophisticated adversary to seize this opportunity to subvert the traditional defense-in-depth posture of many well-established organizations.”

The report goes on to say that:

“The capabilities demonstrated in this campaign – gaining access to SOHO devices of different makes and models, collecting host and LAN information to inform targeting, sampling and hijacking network communications to gain potentially persistent access to in-land devices and intentionally stealth C2 infrastructure leveraging multi-stage siloed router to router communications – points to a highly sophisticated actor that we hypothesize has been living undetected on the edge of targeted networks for years.”

This is a genuine threat. Although your IT department is likely stretched as thin as it is, one of the best ways you can minimize your risk is to assist your employees who are working from home with patch planning to make sure their gear is up to date and as well protected as possible.

How To Easily Create An Efficient Workspace

The more efficient you are, the more effective you are.  That’s true whether you’re working from the office or from home.

Fortunately, most office environments lend themselves to being efficient, so there’s probably not much you need to do on that front. So, the tips below are aimed mostly at those who are working from home.

Having said that, if you want to try and squeeze out a bit more efficiency from your office setup, you can certainly apply these ideas there too!

1 – A second monitor

One thing that’s true about modern work life is that it’s complicated.  On any given day, depending on what you do for a living, you need to access a stunning range of online resources.  So many in fact, that it can be a little overwhelming.

The advent of tabbed browsing has helped somewhat. However, if you find yourself having to access your email system, several locations on your company’s network, and several online applications during  a typical workday, having a second monitor can be a real lifesaver.  Consider it a matter of “dividing and conquering” digital style.

2 – Remove distractions

This is a big one for anyone working from home.  Most offices are inherently designed to minimize distractions. If you’re working from home and have decided to set up shop at the kitchen table, you could find your work day to be absolutely riddled with distractions.

Far better than the kitchen table would be a seldom used spare room if you have one.  A place you can go and shut the door as needed so you can focus on the task at hand.  If that’s not possible, then communication with and understanding from your family is key so they know that when you’re working, you’re working.

3 – A visually interesting space

Our minds don’t tolerate monotony and drudgery very well.  Most people need at least a splash of color to make a space visually interesting to work at something close to peak efficiency.

That will take different forms for different people.  Some might be enchanted by the idea of a small deskside plant.  Others will want a visually interesting picture on the wall or on their desk.  Find your thing.  Find that component that puts your mind at ease and add it to your work environment.  You’ll be amazed at the results!

Efficiency is as much about organization as it is a state of mind.  Both of those elements need to be working in tandem if you want to maximize your efficiency and your productivity.

Conflict Resolution In The Workplace

Conflict in the workplace is sadly inevitable.  Put a group of people in a room together for eight hours or longer every day, week after week. No matter how well they get along, sooner or later, it’s going to happen.

Since it can’t be completely avoided, the next best thing is to have a plan for when it occurs. That’s because if left unaddressed, employee conflicts can ruin morale and permanently damage your company’s culture.  Simply put, letting conflicts in the workplace fester is a very bad idea. The question is what can be done about it?

You’re in luck!  Just below, we’ll outline a few simple things you can do to resolve workplace conflicts before they get out of hand and cause lasting damage to your company.

1 – Address It Head On

When you see two of your employees feuding, they will most likely be sniping at each other with barbs or insults and it may be either in person or via email. No matter what, it is important to address it right away.

Meet with all the participants of the conflict and find out what’s behind it.  There are only two possibilities here and it’s either personal or it’s professional.

2 – How You Address It Matters

In the case of personal differences driving the conflict, you can likely just meet with both parties at the same time.  Sit them down and remind them to keep the personal stuff out of the office.

If it’s professional, it may be best to meet with each side separately so you can get each party’s side of the story and assess from there. Then, involve HR at that point if necessary.

3 – Listen and Seek Input

After hearing from the parties involved about what’s driving the conflict, ask each of them how they’d like to see the issue resolved.

Sometimes, nothing comes from this when both parties may have unrealistic expectations. However, more often than you might think, a solution presents itself from that conversation.

There are several other things you can do to help resolve workplace conflicts, but if you do nothing more than adopt the suggestions above, you’ll be miles ahead of most managers!

Conduct More Effective Meetings With These Simple Tips

Do the meetings you hold tend run off the rails?

Do you find that they frequently run far longer than you intended and that very little actually comes out of them?

If those things are true and if you’re looking for ways to improve the structure of your meetings, here are some quick tips that will help make them more effective:

1 – Consider Your Attendees Carefully

Unless someone’s presence is essential at any given meeting, don’t send them an invite.  Keep the circle as small as possible.  The fewer people, the easier it is to keep the meeting on track.

2 – Laser-Like Focus

Create an agenda for the meeting and stick to it.  Don’t try to do too much.  Focus on one item or two at the most and then hammer out the details and move on.

3 – Prompt Follow-Up

The first two items on this list will practically guarantee that your meeting time is shorter but it won’t necessarily guarantee that the meeting itself was fruitful and productive.

For that, you need quick follow ups, and part of the content of the meeting should be to set aggressive timetables on when deliverables are due.

Once those timeframes are set, it’s on you to follow up and make sure that everybody’s on track and the deliverables will be wherever they need to be by the agreed upon time.

If you adopt these strategies, you may find that you’ll have relatively more meetings than you’re having right now.  The good news is that those meetings will tend to be short, tightly focused, and productive.  In other words, they’ll simply be more effective meetings and at the end of the day, that’s exactly what you want!

Try it and see for yourself.  If you put these tips in practice during your next meeting, you’ll be amazed at the difference.