Twilio denies SendGrid breach after hacker offers 848,000 records for sale
- Organization
- Twilio
- Exploit
- Hacking
- Industry
- Technology
In early April 2025, a threat actor using the alias Satanic posted on the BreachForums cybercrime marketplace offering a dataset the seller said had been taken from SendGrid, the email delivery platform Twilio acquired in 2019. The seller asked $2,000 for the full set and put the record count at roughly 848,000.
Samples circulated by the seller mixed contact details with business intelligence. They included email addresses, phone numbers, physical addresses, cities, states, countries, social media profiles and LinkedIn identifiers, alongside company-level fields such as domain names, revenue, operating and net income, employee headcount, hosting providers, search performance data and technology stack details covering content management, payment and customer relationship platforms. Bank of America, Bazaarvoice and the BBC were among the organizations named in the sample.
Twilio rejected the claim outright. A company spokesperson said there was no evidence to suggest that Twilio or Twilio SendGrid was breached, and that after reviewing a sampling of the data, the company believed none of it originated from SendGrid.
The seller was an established figure on hacking forums, having previously claimed responsibility for a September 2024 compromise of the phone-tracking service Tracelo affecting some 1.4 million users. Coverage of the SendGrid listing noted that the actor had a track record of repackaging previously leaked material, and no independent confirmation of a SendGrid compromise emerged.