Incident log for infosec event involving third party SMS alert provider (Twilio)

Resolved

We want to inform you about a recent incident involving Twilio, our service provider for delivering SMS alert notifications. Twilio uses a network of carriers to ensure reliable message delivery. Unfortunately, one of their subcontractors inadvertently exposed certain SMS-related data publicly on the internet between May 10-15, 2024. This exposure included mobile numbers, SMS message content, sender IDs, and timestamps for messages sent between January 1, 2024, and May 15, 2024. A white hat security research group accessed this data during the exposure period. This incident was outside the control of both Twilio and TrendSpider. Twilio is working diligently with their carriers to address the issue and prevent future occurrences. They have stopped sending traffic through the affected subcontractor and continue to investigate the situation thoroughly. We recommend that users simply be aware that this occurred and be careful with any unsolicited messages that you may receive.

Jul 4, 2024 2:10 am
Affected Systems
System: Alerts
Operational