September 2026 Fraud Update: Phishing Trends, Third-party Safety and Latest Releases
Time to read:
We’re back at it again, builders, with our quarterly fraud update for Q3 2026!
First up, we’re covering some of the latest phishing trends and diving into one particular type of financial scam. We’ll highlight the unique tactics and techniques shared across these attacks, along with steps you can take to keep from getting scammed. We’ll also shine a light on a recent incident involving a Twilio third-party application and cover best practices for sharing credentials safely with any external tools your organization is planning to support. Finally, we’ll wrap up with recent product releases to help prevent fraud and abuse in your accounts. Let’s dig in.
Latest tactics in financial scams in phishing
Our fraud teams actively track top trends and offenders in phishing and other forms of fraud week-over-week. While over 80% of phishing in Q3 originating from SendGrid was due to account takeovers (more on this later), the broader attack trends we observed centered on three main areas:
- Delivery service spoofing: Fake shipping alerts impersonating major carriers like UPS and FedEx
- Invoice fraud: Malicious billing notices designed to extract unauthorized payouts
- Targeted Japanese campaigns: Japanese-language messages spoofing household brands like Amazon and Mercari to target businesses in Japan
Our fraud operations teams have been especially focused on combating fake invoice fraud. This quarter, we tracked several incidents where threat actors impersonated trusted entities as part of larger, coordinated financial fraud schemes. In some cases, these attackers went so far as to impersonate our customers' executives or even Twilio employees.
While financial scams are familiar territory for our security teams, the specific tactics behind these attacks blend old and new techniques:
- Fabricated forwarded threads: Attackers attach fake email histories to their requests to build false credibility and urgency around a wire transfer. In one case, an attacker inserted themselves into a legitimate email thread due to a compromise on the customer's side.
- Typosquatted domains: Attackers send messages from a domain that looks similar to a legitimate organization. For example, some of the examples in our analysis were
service-nowinc[.]comandtvvilio[.]org. - Familiar names: Targets receive emails displaying the name of an actual colleague. For example, you might see ‘Alice Smith’ in the
FriendlyFromheader andalicesmith@tvvilio[.]orgas the sending address. Attackers frequently spoofed company executives or individuals in payments or collections. - AI-generated email templates: These templates use specific words to generate attention and action from the victim, including “ACH payment,” “wire payments,” and requests for payment to fabricated outstanding invoices. These emails also contain artifacts and HTML comments often generated by AI.
- Associated phone calls: In multiple cases, attackers attempted to call the victim, sometimes from a spoofed number (in one such case, a spoofed Twilio help line!). Twilio will never call you unsolicited to request payment or to request your login information.
Twilio takes down malicious domains and continuously improves our own platform detections, but customers have a responsibility as well. Scan all incoming and outgoing email traffic for malicious attachments, ransomware, phishing links, and social engineering threats. Make sure inbound emails undergo initial verification and filtering before being delivered. Also, although email authentication methods (SPF, DKIM, DMARC) should be used to prevent spoofing of your domain, keep in mind that these won’t prevent your organization from receiving emails from typosquatted domains.
Finally, make sure your employees are aware of these tactics and know to submit any suspicious emails or calls to your security team. For phishing or spoofing involving SendGrid, open a ticket or reach out to abuse@sendgrid.com.
Providing credentials to third-party applications
Keeping your integrations secure requires diligent vendor vetting, enforcing the principle of least privilege, and running regular security audits. While third-party tools and integrations are essential for operational efficiency, implementing intentional controls is critical. Recent security incidents involving third-party providers across the industry demonstrate how quickly a compromised integration can lead to serious financial and operational damage.
If bad actors breach a third-party application, they can access stored Twilio API credentials to call Twilio APIs directly. To balance the convenience of third-party tools with a strong security posture, put these practices in place:
- Scope access strictly: Avoid sharing main authentication tokens or main/standard API keys with external applications. Instead, provide restricted API keys limited to the exact endpoints the integration needs. This limits the blast radius if the third-party tool is compromised.
- Practice active credential hygiene: Set up regular rotation schedules for API keys used by third-party integrations. Better yet, you can implement automatic auth token detection and rotation.
- Review audit integrations regularly: Review active third-party connections across your environment and immediately revoke access for stale, unused, or unverified tools.
New releases for securing your account
We’re rolling out several platform and security updates in Q3 through the rest of the year to help you protect your applications and data across the Twilio platform.
OAuth 2.0 Client Credentials
For applications connecting to Twilio APIs, (third-party integrations or your own internally-owned services), we now recommend OAuth 2.0 Client Credentials over auth tokens or API keys. Account OAuth apps support the Client Credentials grant type and let you generate scoped, short-lived access tokens instead of using long-lived, account-wide credentials.
To set it up, create an OAuth App in the Twilio Console, select the specific scopes it needs and set a token lifetime, and the app receives a Client ID and Client Secret that it exchanges for access tokens via the Token API. Full details are in the feature doc. OAuth is supported natively across all of Twilio's server-side SDKs, so adopting it doesn't require dropping down to raw API calls. See the SDK support docs for setup details.
OAuth 2.0’s benefits over Auth Tokens and API Keys include:
- Scoped access: Permissions can be limited to exactly what the integration needs rather than granting full access.
- Short-lived credentials: Token expiration is configurable from as low as one minute up to 30 days (default one hour). A compromised access token has a tiny window of usefulness, sharply reducing blast radius compared to a static Auth Token or API Key that stays valid indefinitely.
- Safer secret rotation: Clients secrets can be rotated with a configurable grace period (0–30 days), so integrations can be updated without a hard cutover or downtime.
IP ACL and Dry run mode
Twilio is developing IP based Access Control Lists (ACLs), and the feature is currently available in private beta. This feature will enable businesses to restrict API access to their Twilio accounts exclusively to machines working within their corporate network.
As a part of this private beta, we have also launched a self-serve version of IP ACL's Dry Run mode natively in the new Twilio Console. Dry Run mode lets a customer validate their IP allowlist before real enforcement kicks in. When enabled, ACL validation still runs but never blocks traffic; it simply logs which requests would have been blocked to Event Streams. This lets the customer catch legitimate IPs they forgot to allowlist before switching to actual enforcement. It's effectively a "shadow mode" that prevents accidental lockouts.
IP ACL remains a private beta product today, so it is gated behind an account flag. Customers who want early access can request enablement by reaching out to their technical account manager or contacting Twilio Support. Looking ahead, IP ACL is on track to move to General Availability soon and become part of our Security and Enterprise Editions offerings.
We hope you’ve learned a bit about the latest trends we’ve observed in phishing and third-party security, as well as what new releases can help you on your fraud-free journey with Twilio. Until next time, cheers!
Related Posts
Related Resources
Twilio Docs
From APIs to SDKs to sample apps
API reference documentation, SDKs, helper libraries, quickstarts, and tutorials for your language and platform.
Resource Center
The latest ebooks, industry reports, and webinars
Learn from customer engagement experts to improve your own communication.
Ahoy
Twilio's developer community hub
Best practices, code samples, and inspiration to build communications and digital engagement experiences.