Twilio became aware on 4 August 2022 that someone had walked into its internal systems using a stolen employee password, and it published the fact three days later, on 7 August. The way in was a text message. Current and former staff received SMS purporting to come from Twilio's IT department, telling them their password had expired or their shift schedule had changed, with a link to a login page that looked exactly like Twilio's. Enough of them typed their credentials into it. Twilio said on 10 August that around 125 customer accounts had been reached; the final incident report it closed in October revised the count upward, to 209 customers and 93 end users of the Authy two-factor app.

One of those customers was Signal, which used Twilio to deliver registration codes by SMS. On 15 August Signal told 1,900 users that their phone numbers, and in some cases the verification codes sent to them, had been exposed — and that within the 1,900 the attacker had explicitly searched for three particular numbers. One of the three was re-registered onto another device. Lorenzo Franceschi-Bicchierai, then a reporter at Vice's Motherboard, said publicly that his was one of the three. Message history, contact lists and profile data were never at risk, because Signal keeps them on the device or behind a user PIN; what leaked was the fact of registration, and the means to take it over.

Cloudflare had already been through the same attack and survived it. At 22:50 UTC on 20 July, more than a hundred text messages arrived in under a minute — to employees, and to some of their family members — sent from four T-Mobile-issued numbers and pointing at a domain called cloudflare-okta.com that had been registered less than forty minutes earlier. Three employees believed it and entered their credentials, which the phishing page relayed onward in real time along with their one-time codes. It made no difference. Cloudflare issues every employee a FIDO2 hardware security key bound to the origin it was registered for, and the key will not sign for a domain that is not the real one. The attacker had the password, had the code, and had nothing.

Cloudflare published the account on 9 August, adding that most organisations would likely have been breached. On 25 August Group-IB named the campaign 0ktapus, for the Okta sign-on pages it imitated, and counted more than 130 compromised organisations and at least 9,931 stolen credentials going back to March 2022, over half captured with a live one-time code and funnelled into a Telegram bot. Cisco, breached by a different crew, confirmed on 10 August that the way in had been an employee's personal Google account syncing Cisco passwords out of Chrome, then phone calls and repeated push prompts until one was approved. Yanluowang claimed the intrusion; Cisco said no products or services were affected. The difference between the three companies was not vigilance. It was what the second factor was made of.

Also that month · Back to pen and paper

The supplier that took NHS 111 down

On 4 August 2022 Advanced, a British software supplier, pulled part of its infrastructure offline after detecting an intrusion. What went down with it was Adastra, the patient-management system that NHS 111 call handlers use to log and triage calls — so the people answering Britain's non-emergency medical line spent the following days working on paper, and what sat behind them, out-of-hours GP bookings and patient referrals among it, slowed accordingly. Some services took weeks to come back fully. Later analysis identified the ransomware as LockBit 3.0. The Information Commissioner's Office eventually established how the attackers got in: valid credentials on a customer account with no multi-factor authentication, used to open a remote desktop session on a Citrix server. The personal data of 79,404 people was taken, including, for 890 people receiving care in their own homes, the instructions for how to get into the house. The ICO issued a provisional penalty of £6.09 million in August 2024 and settled at £3.07 million in March 2025.

Also that month · A sentence that aged badly

LastPass loses its source code

On 25 August 2022 LastPass's chief executive, Karim Toubba, told customers that unusual activity had been detected in portions of the company's development environment roughly two weeks earlier — placing the intrusion and its detection in mid-August, and the public disclosure at the end of the month. A single compromised developer account had been used to take portions of source code and proprietary technical information. The notice was carefully worded and, on its own terms, correct: master passwords were not compromised, encrypted vault data was not accessed, and there was no evidence customer data had been touched. What it could not say was what the stolen material would later be used for. In November LastPass disclosed a second incident; in December it confirmed that information taken in August had been used to obtain a cloud-storage backup of customer vault data. A further update in February 2023 filled in the mechanism: a senior DevOps engineer's home computer, and the keys held on it.

India desk · August 2022

Back to a blank page

On 3 August 2022 the Union minister for electronics and information technology, Ashwini Vaishnaw, moved in the Lok Sabha to withdraw the Personal Data Protection Bill, 2019. It went through on a voice vote, and nearly five years of work with it. The bill descended from the Supreme Court's Puttaswamy judgment of August 2017, which held privacy to be a fundamental right, and from the Srikrishna Committee draft that followed. A Joint Committee of Parliament had spent two years on it and tabled its report in December 2021, proposing 81 amendments to a bill of 99 clauses along with broader recommendations. That is not a revision; it is a request to start again. The government said as much, arguing that what was needed was a comprehensive framework, not a patched one.

The criticisms of what was withdrawn were real: the bill had grown to cover non-personal data and hardware certification, and it exempted state agencies broadly enough that members of its own committee filed dissents. But the practical effect was that India, in August 2022, had the world's second-largest population of internet users, a national identity system, a real-time payments network carrying billions of transactions a month — and no dedicated statute governing what could be done with the data any of it produced. Meanwhile CERT-In's directions of April 2022, requiring incident reporting within six hours, were coming into force regardless — so breaches had to be reported quickly to the state, while nobody owed the affected person anything. The replacement draft arrived in November 2022, was passed as an Act in August 2023, and then spent years more waiting on the rules that would make it operable.

AI Tech desk · August 2022

An image generator anyone could download

On 22 August 2022 Stability AI released the weights of Stable Diffusion under an open licence, and text-to-image generation stopped being a service and became a file. Built with academic researchers in Munich, Runway and the LAION dataset project, the model drew 512-pixel squares on a single consumer graphics card, and within days it was being forked, fine-tuned and bolted into other people's software. The closed systems kept shipping around it: Meta released its BlenderBot 3 chatbot on 5 August and watched it produce unflattering opinions of the company's own chief executive within the week, and OpenAI added outpainting to DALL·E on 31 August, letting an image grow beyond its original borders. On 29 August, judges at the Colorado State Fair gave first prize in the emerging-artist division of the digital-arts category to Théâtre D'opéra Spatial, a work Jason M. Allen had generated with Midjourney and finished in Photoshop; the wider press only noticed in the first days of September. Four years on, Stable Diffusion's descendants are everywhere — and so are the lawsuits it seeded.

Digital Guard desk · August 2022

Two identity companies, one buyer

On 3 August 2022 Thoma Bravo agreed to take Ping Identity private at $28.50 a share in cash — a valuation of roughly $2.8 billion, and a premium of about sixty per cent on the previous day's close. Thirteen days later the same firm completed its roughly $6.9 billion purchase of SailPoint, another identity specialist. With public valuations well below their 2021 peak, private equity spent 2022 buying security companies at prices boards found easier to accept than their share charts — and identity, the layer 0ktapus had spent the summer phishing, was where the money concentrated. Further down the market the squeeze showed differently: Malwarebytes cut about 125 jobs in August, roughly one employee in seven, saying it would concentrate on smaller businesses. Thoma Bravo closed the Ping deal in October, added ForgeRock and merged the pair in 2023; SailPoint was back on the public markets by early 2025; and Malwarebytes now sells its corporate line under the ThreatDown name.

⏳ Time capsule — August 2022

  • The FBI executed a search warrant at Mar-a-Lago on 8 August, removing boxes of government records from the former US president's Florida residence.
  • Serena Williams announced in a Vogue essay published on 9 August that she was "evolving away from tennis" — a word she said she preferred to retirement.
  • House of the Dragon premiered on HBO on 21 August, drawing close to 10 million US viewers across linear and streaming on its first night — the largest series launch in the network's history.
  • Mikhail Gorbachev, the last leader of the Soviet Union, died on 30 August, aged 91.
Where it stands today — 2026

The month the second factor stopped being enough

0ktapus and Scatter Swine were early names for a set of people the industry has spent the four years since renaming. The technique barely changed: a text message to an employee, a login page that looked right, and a relay that passed the one-time code onward while it was still valid. By mid-September 2022 a close variant — a contractor's stolen credential and a stream of push prompts — had reached Uber. By September 2023, under the name Scattered Spider, the approach had shut down casino floors in Las Vegas, and by 2025 it was working its way through British retailers. Nothing about it was technically clever, which is exactly the point. It was cheap, patient, and it defeated every second factor a human being could read out loud.

The counter-argument Cloudflare published on 9 August became policy: origin-bound hardware keys went from Silicon Valley eccentricity to audit question, and "phishing-resistant" turned into a phrase in national guidance rather than a vendor slogan. Advanced's penalty, settled at £3.07 million in March 2025, carries the other lesson — that a health service can be taken off its computers by a supplier most of its patients have never heard of, a shape this archive meets again in February 2024. LastPass is why we date things carefully: everything the company said on 25 August 2022 was true, and four months later none of it still described the situation. In Delhi, the blank page stayed blank for another year.