Twilio Hack 2022: How One Text Breached a Telco Platform

Picture the message as it landed. A work notification on a personal phone, apparently from the IT department: your password has expired, sign in here to reset it. Or, for some recipients, a note that their shift schedule had changed, with a link to check it. The link went to an address with the company name and the words "sso" or "okta" in it, and the page it opened looked exactly like the sign-in screen staff used every day. That is how the Twilio hack began in the first days of August 2022. A few employees typed in their username, password and one-time code, the attackers used those details on the real system within seconds, and from there they reached the internal tools Twilio staff use to support customers. Twilio detected the intrusion on 4 August, and the last unauthorised activity was on 9 August. By the time the investigation closed, 209 customer accounts had been accessed, 93 users of the Authy authenticator app had strange devices attached to their accounts, and Signal, the encrypted messaging app, had told around 1,900 of its users that their phone numbers or registration codes may have been exposed. There was no zero day exploit and no malware on a server. There was a text message, a copied page and a code that proved much less than everyone assumed. This article walks through the chain link by link, because each link has a direct equivalent in an Australian small business, and most of them can be fixed in a month.

Security Deep Dive · 2026

"Your Password Has Expired." Five Days Later, 209 Accounts.

The Twilio hack is usually told as a story about a big American tech company. It is more useful told as a chain: a text message, a copied web page, a six digit code, an internal support tool, and finally the accounts of people who had never heard of Twilio. Every link in that chain has an equivalent in an ordinary Australian business, and most of them are still unguarded. We rebuilt the incident step by step from the public record, looked at the company that got the same texts and lost nothing, and turned it into a plan you can start this month.

📅 ⏱ 17 min read 🇦🇺 Australian owned · Australian network · Australian support
TL;DR

The Twilio hack was a chain of six ordinary steps: a fake IT text, a copied sign-in page, a relayed six digit code, access to internal tools, a search of customer accounts, and exposure of those customers' own users. The result was 209 customer accounts accessed, 93 Authy users affected and around 1,900 Signal users exposed. Cloudflare got the same texts and lost nothing because its staff used hardware security keys that ignore fake websites. An SMS code proves someone has a phone for a moment, not who they are or where they are typing. In 2024 a second incident let attackers confirm around 33 million Authy phone numbers, which is a reminder that numbers are targeting data. For your business: treat your phone and SMS provider as part of your security, move staff to passkeys or hardware keys, stop relying on SMS codes for anything valuable, and use the provider scorecard below.

A Text That Looked Routine

Security incidents are usually described from the defender's side: detection, containment, notification. To understand why this one worked, it helps to start from the other end, with the person holding the phone.

They are at home, or on a train, or waiting for a coffee. A text arrives. It does not look like the scam texts everyone has learned to ignore. There is no parcel, no toll road, no tax refund. It says their work password has expired, or their roster has changed, and gives a link. The link has their employer's name in it. The page it opens is the same sign-in page they see every morning, down to the logo and the layout. It asks for their username and password, and then for the code that has just arrived on their phone. They type it. Maybe the page says something went wrong. Maybe it just moves on. Either way, they get on with their day.

Nothing about that sequence feels like a mistake while it is happening, and that is the whole point. The people who designed the Twilio messages were not trying to fool somebody careless. They were trying to look exactly like a routine interaction with IT, and they succeeded. Researchers who later studied the wider campaign found it had targeted more than 130 organisations the same way.

The most dangerous phishing is not the message that looks strange. It is the one that looks exactly like something your staff do every week. Password resets, roster changes, shared documents and invoice approvals are the templates, because nobody thinks twice about them.

Six Links From a Text to a Stranger

Here is the Twilio incident rebuilt as a chain. For each link we have put the equivalent in a typical Australian business of twenty to two hundred people, and the control that breaks it.

  1. The text reaches a personal mobile

    Attackers had employee phone numbers, very likely compiled from data brokers and earlier breaches. Your version: staff mobile numbers are on LinkedIn, in email signatures and in every leaked database. What breaks it: nothing, realistically. Assume the message will arrive.

  2. The link opens a copy of the sign-in page

    Domains such as twilio-sso.com and twilio-okta.net looked official on a small screen. Your version: a copy of your Microsoft 365 or Google sign-in page on a lookalike domain costs an attacker almost nothing. What breaks it: a rule that IT never sends sign-in links by text, so every such message is fake by definition.

  3. The password and code are relayed

    The phishing kit sent what the employee typed to the attackers in real time, and they replayed it on the real site before the code expired. Your version: exactly the same, against SMS or app codes on your email. What breaks it: passkeys or hardware keys, which will not answer a lookalike site at all.

  4. The attackers reach internal tools

    With an employee's identity, they got into systems staff use to manage customer accounts. Your version: your email, your accounting package, your phone system admin portal. What breaks it: limiting who can reach admin tools, and requiring stronger sign-in for those tools specifically.

  5. They search for specific customers

    The activity focused on particular customer accounts, and within them particular phone numbers. Your version: an intruder in your systems looking up your largest clients or your payment details. What breaks it: access logs that someone actually watches, and alerts on unusual lookups.

  6. The customers' own users are exposed

    Signal users who had never dealt with Twilio found their numbers or registration codes exposed. Your version: your customers, exposed because of a breach at a provider you chose. What breaks it: choosing providers carefully, and limiting what they hold.

Only one of those six links is about a clever technical trick, and even that one, the relayed code, is available off the shelf. The rest are about who has access to what, and whether anybody notices. That is encouraging, because those are things a small business can change without a security team.

One more link belongs at the front of the chain. Twilio's investigation found that on 29 June 2022, more than a month before the texts, an employee had been talked into giving up credentials during a phone call, and limited customer contact information had been viewed. Before the attackers tried text messages at scale, they had already tried a conversation. The same people and methods have since been linked by researchers to the group known as Scattered Spider, which has leaned heavily on phone calls to help desks in the years since.

The Numbers, Without the Spin

209
Twilio customer accounts accessed, out of more than 270,000
93
Authy users who had unauthorised devices added to their accounts
~1,900
Signal users whose numbers or registration codes may have been exposed
5 days
From detection on 4 August to the last unauthorised activity on 9 August 2022

There are two ways to read these figures and both are correct. On one reading, 209 accounts is a tiny fraction of Twilio's customer base, no customer passwords, authentication tokens or API keys were found to have been taken, and the intruders were out within days. On the other reading, a single text message gave outsiders a path to the accounts of hundreds of businesses and, through them, to the users of an app built specifically for privacy.

The first reading is the one that matters to Twilio. The second is the one that matters to you, because in any supply chain breach you are either the platform or one of the 209, and a small business is never the platform.

It is also worth being precise about what the Signal exposure was. For around 1,900 users, either the fact that their number was registered to Signal was potentially revealed, or the SMS code used to register the account was exposed. Signal said the attacker searched explicitly for three numbers, and one of those three users reported their account had been re-registered to another device. Message history, contacts and profile information were not exposed, because Signal does not store them anywhere Twilio could reach. That design choice is a large part of why the damage was contained.

What Twilio Got Right

It is easy to treat a breached company as a cautionary tale and nothing more. That is not fair to Twilio, and it is not useful either, because several things it did are worth copying.

🔍

It noticed

Detection came within days of the texts. Many businesses discover intruders months later, usually because someone else tells them.

📢

It said so publicly

A public notice went out three days after detection and was updated as the numbers changed. Customers were not left to learn about it from the press.

🔑

It fixed the root cause

Twilio issued FIDO2 hardware tokens to all employees, rather than just running another round of phishing training.

🧱

It tightened the edges

Stronger controls on VPN and administrative tools, more frequent re-authentication for connected apps, and social engineering training for staff.

The third item is the one to underline. The instinctive response to a phishing incident is more training, and training has a place. But the people who typed their details into the fake page were not unusually careless, and more training would not have made them immune. Changing how staff sign in removed the thing the attackers needed. Twilio got there after the fact. Another company had got there before.

The Company Where Nothing Happened

At almost the same time, Cloudflare, the internet infrastructure company, received the same style of text messages. Seventy-six employees were targeted, some through their family members' phones. Three of them clicked through and entered their credentials on the fake page.

No account was compromised. Cloudflare's staff sign in with FIDO2 hardware security keys. When a key is asked to confirm a sign-in, the browser tells it which website is asking, and the key only responds to the site it was registered with. The phishing page was on a different domain, so the key simply did not answer. There was no code on screen, nothing to type and nothing to relay.

Two questions that usually get blurred together

Will your staff ever be fooled? Yes. Cloudflare employs some of the most security aware people in the industry, and three of them still typed passwords into a fake page. Will being fooled become a breach? That depends on how they sign in, and it is entirely within your control. Stop measuring success by whether anyone clicks. Measure it by whether a click can do any damage.

In 2022 hardware keys were mostly something large tech companies handed out. In 2026 the same protection is available as passkeys, which live on a phone or laptop and unlock with a fingerprint or face, and which Microsoft 365, Google Workspace and most business platforms now support. The price of Cloudflare's outcome has dropped to roughly nothing.

You Are Somebody’s Signal

This is the part of the story that should change how you think about your phone and SMS provider.

Signal had done a great deal right. It encrypted messages end to end and stored as little as possible. Its weak point was not its own engineering. It was a supplier that sent verification texts on its behalf. When that supplier's staff were phished, Signal's users were exposed, and they had never agreed to trust Twilio. They had agreed to trust Signal.

Now swap the names. Your customers trust your business. When you text them an appointment reminder, a quote, a payment link or a verification code, that message goes through a provider. When they ring your number, the call is routed by a provider. Your customers have no idea who that provider is. If its support tools are compromised, an intruder may be able to read your messages, redirect your number, or send texts that look like they came from you. Your customers would reasonably blame you.

You send or receiveYour provider can see or controlIf the provider is compromised
Appointment and booking textsCustomer names, numbers and appointment detailsA targeting list for scams that reference real bookings
Verification codesThe codes themselves, as they pass throughAccount takeover for your customers
Inbound calls to your main numberRouting and forwarding rulesCalls diverted to someone pretending to be you
Call recordings and transcriptsStored conversations, often with personal detailsA privacy breach with your name on it
Branded SMSYour registered sender identityMessages that look genuinely from you, sent by someone else

The practical point is not that big platforms are dangerous and small ones are safe. It is that the number of organisations between you and your customers matters, and so does how each one protects its own staff tools. A cheap SMS gateway is often a reseller passing your messages to another reseller, sometimes across several countries, before they reach a carrier. Every company in that chain is a potential Twilio. We wrote about why that layering matters for AI services too in who actually runs the infrastructure.

What an SMS Code Actually Proves

Businesses use SMS codes everywhere: staff sign-in, customer verification, password resets, payment approvals. It is worth being exact about what one proves, because the Twilio incident turned on the difference.

What people assume the code provesWhat it really proves
This is the right person.Someone had access to messages for this number in the last few minutes.
They are signing in to our real site.Nothing about where the code was typed. It works just as well on a fake page that relays it.
The phone is in their hand.The number is currently routed to some SIM. After a SIM swap, that SIM belongs to someone else.
The message was private.It passed through at least one provider, and possibly several, any of which could see it.

Authenticator app codes fix the third and fourth rows, because they are generated on the device rather than sent over the network. They do not fix the second row, and the second row is what the Twilio attackers used. Only methods where the browser checks the website on the person's behalf close it. That means passkeys and hardware keys.

For staff, the conclusion is straightforward: move to passkeys or hardware keys, and remove SMS as a recovery option where you can. For customers it is more nuanced. SMS codes are still a reasonable convenience for low risk actions, and they are far better than nothing. For anything valuable, such as changing bank details, redirecting deliveries or approving a large payment, add a second check that does not depend on the phone number alone, such as a callback to the number already on file or a question only the real customer can answer.

SIM Swaps and the Australian Rules

A SIM swap is the attack that turns an SMS code into the attacker's code without any phishing at all. Someone persuades a mobile carrier to move a victim's number to a new SIM. From that moment, every text sent to "the victim's phone" arrives on the attacker's phone instead, including every verification code.

Australia has done more than most countries to make this harder. ACMA rules require telcos to use multi-factor identity checks before high-risk transactions such as SIM swaps, number ports and changes to account details, and to tell customers how they protect them. We publish how that works for VOCPhone accounts on our customer identity authentication page. The rules have cut the easy version of the attack substantially. They have not eliminated it, because determined attackers combine stolen personal details with a convincing story, and some target business numbers rather than personal ones.

The business number is a target too

Most SIM swap advice is aimed at personal mobiles. A business number that receives verification codes for your bank, your accounting platform or your domain registrar is worth more to an attacker than any individual's phone. Know which of your accounts send codes to which numbers, and make sure the business numbers are protected by account-level security with your provider, not just by the fact that nobody knows them.

The broader Australian environment has also shifted since 2022. The SMS Sender ID Register became mandatory on 1 July 2026, so branded texts from unregistered names now arrive labelled "Unverified", which we covered in our Sender ID guide. Telco consumer protections are moving into direct regulation, as set out in our explainer on the new rules. The Scams Prevention Framework places new obligations on banks, telcos and digital platforms. All of this makes a genuine, registered business message more trusted than it was, which is good for honest senders and also makes the ability to send one more valuable to steal.

The Second Lesson: Numbers Are Data

In late June 2024, the ShinyHunters group posted a file of around 33 million phone numbers tied to Authy accounts. Twilio confirmed the list had been built using an Authy interface that did not require authentication: feed it phone numbers, and it would confirm which ones belonged to Authy users, with basic account details. Twilio closed the interface to unauthenticated requests and asked users to update their apps. No passwords or codes were exposed.

A list of phone numbers sounds harmless. A verified list of people who use a particular security app is not. It tells an attacker exactly who to text pretending to be Authy support, who to target for a SIM swap, and who is likely to have valuable accounts worth protecting. The same group name turned up again in 2026 behind the extortion campaign that hit RingCentral and many other companies through social engineering. The method has moved on from mass texts to phone calls and help desk impersonation. The principle has not: collect enough small facts about people, then use them to sound legitimate.

Two lessons for a business. First, every interface you expose, including a simple "is this number registered" check on your own website or app, should require authentication and limit how fast it can be queried. Second, your customer phone list is sensitive data even if it contains nothing else. Treat it with the same care as payment details, and ask your providers how they protect it.

What to Do, Role by Role

In a business of twenty to two hundred people, security is rarely one person's job. Here is what each role can do, based directly on the Twilio chain.

RoleActions
Owner or managing directorDecide that staff sign-in moves to passkeys or hardware keys and fund it. Ask your phone and SMS provider the scorecard questions below. Make it clear that reporting a mistake is always the right thing to do.
Whoever looks after ITList every system still using SMS codes. Issue hardware keys to anyone with admin, finance or phone system access. Turn on passkeys everywhere else. Remove SMS fallback. Confirm IT never sends sign-in links by text.
Office or practice managerCheck who can change call routing, forwarding and numbers in your phone system, and cut it down to the people who genuinely need it. Make sure your provider has an account PIN or equivalent set.
Whoever sends customer SMSConfirm your sender identity is registered. Tell customers what your genuine messages look like and what you will never ask for by text. Stop sending links that ask customers to sign in.
Front desk and customer serviceNever act on account changes requested by inbound call or text without a callback to the number on file. Never read out or ask for a verification code on a call. Escalate anything urgent that cannot be verified.
EveryoneGo to the site yourself instead of following a link. Report anything odd, especially if you already clicked.

The front desk row is where the Twilio playbook meets 2026. The groups linked to these campaigns now prefer to ring, often pretending to be IT support or a customer in a hurry, and AI voice cloning has made the voice itself unreliable as evidence. Our piece on voice cloning and vishing covers that side in detail, and what AI security catches on the phone covers where technology can help.

A Provider Security Scorecard

Score your current phone and SMS provider on each line. Two points for a clear yes, one for a partial answer, zero for no or no answer. Anything under fourteen out of twenty deserves a harder conversation.

QuestionWhy it matters after Twilio
Do your staff use phishing-resistant sign-in for tools that manage my account?This is the control that separated Twilio's outcome from Cloudflare's.
Is access to my messages and recordings limited to named roles and logged?The attackers used internal support tools to look up specific customers.
Can I get an access log for my account?You cannot assess your exposure without one.
Do you follow ACMA identity checks before ports and SIM or account changes?The Australian defence against SIM swaps and number hijacks.
Can you name the country and the operator that hosts my data?"The cloud" is not a jurisdiction.
How many other companies handle my calls and texts in transit?Each one is another link in your chain.
Will you commit in writing to an incident notification timeframe?You may have your own obligations to customers once you know.
Does every API endpoint require authentication and rate limiting?The 2024 Authy exposure came from one that did not.
Can I restrict who in my business changes routing and numbers?Limits what a phished staff member of yours can break.
Is support in-house and trained to refuse unverified urgent requests?Help desks are where these groups now start.

If you are weighing a change of provider for this or any other reason, our guide to what goes wrong when switching covers the practical risks, including how to port numbers without a gap.

This Month, This Quarter, This Year

HorizonDo this
This monthBrief staff: IT never texts sign-in links, go to the site yourself, report even if you clicked. List every system using SMS codes. Hardware keys for admins and finance, with a spare each. Send your provider the scorecard.
This quarterPasskeys for all staff on email and core systems. SMS fallback removed wherever possible. Phone system admin rights cut back to the people who need them. Customer verification reviewed so high value changes need more than an SMS code. Sender ID registered.
This yearReview every supplier that holds customer contact data, not just your phone provider. Test your front desk with a friendly fake call. Write down who you call and what you tell customers if a supplier is breached, before you need it.

The expensive part of all this is a week or two of staff getting used to a fingerprint or a key tap instead of a code. Compared with explaining to your own customers that their details were exposed through a supplier they never heard of, it is a bargain.

Where We Stand

VOCPhone carries calls and SMS for Australian businesses, so we are in the position Twilio was in: a supplier inside our customers' trust chain. We think the right response is to keep that chain short and be plain about it.

We own and operate our own network in Australia rather than reselling somebody else's, which means fewer companies sit between your business and your customers. The platform is Australian owned and Australian hosted. Business SMS goes out from your own recognised business number, so customers see a sender they already know. Number ports and high-risk account changes go through identity checks under ACMA's customer identity authentication rules, and our support team is Australian, available around the clock, and trained not to act on urgent requests it cannot verify. We explain more about why owning the network matters in we own the network.

If you would like to run the scorecard against us, or want help working out where SMS codes are still holding up your security, we are happy to go through it line by line.

Run the scorecard on us

Ask us the ten questions and get straight answers from an Australian team, or have us look at how your business sends SMS, verifies customers and locks down its phone system settings.

Talk to us Or call 1300 663 222

Frequently Asked Questions

How did the Twilio hack happen?
It began with text messages. In early August 2022, current and former Twilio employees received SMS messages that pretended to come from the company IT department, saying their password had expired or their schedule had changed. The messages linked to lookalike domains such as twilio-sso.com and twilio-okta.net, which displayed a copy of the company's sign-in page. Employees who entered their username, password and one-time code handed them to the attackers, whose phishing kit relayed the details in real time so they could be used on the real site before the code expired. With those identities, the attackers reached internal tools Twilio staff use to support customers, and looked up specific customer accounts. Twilio detected the intrusion on 4 August 2022 and the last unauthorised activity was on 9 August. The investigation also found an earlier incident on 29 June 2022 in which an employee was manipulated on a phone call and limited customer contact information was viewed. The final tally was 209 customer accounts accessed out of more than 270,000, and 93 Authy users with unauthorised devices added. Twilio found no evidence that customer passwords, authentication tokens or API keys were taken.
Who was affected by the Twilio breach?
Directly, 209 Twilio customer accounts were accessed, and 93 individual users of Authy, Twilio's authenticator app, had additional devices registered to their accounts without permission. Indirectly, the customers of those customers were affected, and the best documented example is Signal. Signal used Twilio to send the SMS codes that verify phone numbers when people register, and it disclosed that for around 1,900 users, either their number was potentially revealed as registered to Signal or their registration code was exposed. Signal said the attacker searched explicitly for three numbers and one of those users reported their account had been re-registered on another device. Messages, contacts and profile data were not exposed. The same campaign, which researchers at Group-IB named 0ktapus, targeted more than 130 organisations using similar texts and fake sign-in pages, so Twilio was one victim among many. For an Australian business, the important category is the indirect one. Signal's users never chose Twilio, yet a breach at Twilio reached them. Your customers are in the same position with whatever provider carries your calls and texts, which is why that provider's internal security is part of your own.
Why did Cloudflare avoid the same attack?
Because of how its staff signed in. Cloudflare received the same style of text messages at around the same time as Twilio. Seventy-six employees were targeted and three of them entered their credentials on the fake sign-in page, so the phishing itself worked about as well as it did anywhere else. What failed was the next step. Cloudflare staff used FIDO2 hardware security keys as their second factor instead of one-time codes. When a hardware key is asked to approve a sign-in, the browser tells it which website is making the request, and the key only responds to the website it was originally registered with. The fake page sat on a different domain, so the key never answered, and there was no code on screen for the employee to type or for the attackers to relay. The lesson is that you cannot rely on people never being fooled, since even very security aware staff will occasionally click. You can make sure being fooled does not hand over anything reusable. In 2026 that protection is available to small businesses as passkeys on phones and laptops, supported by Microsoft 365, Google Workspace and most business platforms, as well as through hardware keys for higher risk roles.
What does an SMS verification code actually prove?
Much less than most businesses assume. It proves that someone had access to messages for a particular phone number within the last few minutes. It does not prove that person is who they claim to be, because a SIM swap can move the number to an attacker's SIM. It does not prove where the code was typed, because a phishing page can relay it to the real site, which is exactly what happened in the Twilio attack. And it is not private, because the code passes through at least one provider and sometimes several on its way to the phone. Authenticator app codes are better, since they are generated on the device and cannot be intercepted by a SIM swap, but they can still be typed into a fake page and relayed. Passkeys and hardware keys are different in kind: the browser checks which website is asking, so a lookalike site gets nothing. For staff sign-in, move to those methods and switch off SMS as a recovery option. For customers, SMS codes remain a reasonable convenience check for low risk actions, but anything valuable, such as changing bank details or approving a payment, should need a second check that does not depend on the phone number alone.
Can a SIM swap happen to a business in Australia?
Yes, although it is harder than it used to be. A SIM swap is when an attacker persuades a mobile carrier to transfer someone's phone number to a SIM the attacker controls. From that moment every call and text, including verification codes, goes to the attacker. Australian rules made by the ACMA require telcos to use multi-factor identity checks before high-risk transactions such as SIM swaps, number ports and account changes, and to publish information about how customers are protected. Those rules have cut down the easy versions of the attack considerably. Determined attackers still try, usually by combining personal details stolen in earlier breaches with a convincing story, and business numbers can be more attractive than personal ones because they often receive codes for banking, accounting and domain accounts. The practical steps are to know which accounts send codes to which numbers, to move important accounts off SMS codes altogether, and to make sure your business numbers are protected with account-level security such as a PIN or verified contact list with your provider. VOCPhone publishes how identity checks work for its accounts on its customer identity authentication page, and any provider should be able to explain the same for yours.
What was the Authy data exposure in 2024?
In late June 2024, the ShinyHunters group published a file of around 33 million phone numbers linked to Authy, Twilio's authenticator app. Twilio confirmed that the list had been assembled using an Authy interface that did not require authentication. Attackers submitted large volumes of phone numbers and the interface confirmed which belonged to Authy accounts, along with basic details such as account status and device count. Twilio secured the interface so it no longer accepted unauthenticated requests and recommended that users update the Android and iOS apps. It said it had seen no evidence that attackers accessed its systems or other sensitive data, and no passwords or codes were involved. The significance is in what the list enables. A verified set of people who use a particular security app is a ready-made target list for texts impersonating that app's support team, for SIM swap attempts and for phone calls pretending to be a help desk. For a business, there are two takeaways. Any lookup you expose, even a simple check of whether a number is registered, should require authentication and be rate limited. And your customer phone list is sensitive data in its own right, which deserves the same care as payment information.
How do I know if my phone and SMS provider is secure?
Ask specific questions and judge the answers. Start with how the provider's staff sign in to the tools that manage your account, since phishing-resistant methods like hardware keys or passkeys are the control that separated Twilio's outcome from Cloudflare's. Ask whether access to your messages and call recordings is limited to named roles and logged, and whether you can get an access log for your account. Ask whether they follow ACMA's customer identity authentication rules before number ports, SIM changes and account changes. Ask them to name the country and the operator that hosts your data. Ask how many other companies handle your calls and texts in transit, because resellers and overseas gateways each add another link to your chain. Ask for a written commitment on how quickly they will notify you of an incident affecting your account. Ask whether every API endpoint requires authentication and rate limiting, since the 2024 Authy exposure came from one that did not. Ask whether you can restrict who in your own business can change routing and numbers. And ask whether support is in-house and trained to refuse urgent requests it cannot verify. Scoring two points for each clear yes gives a quick measure, and anything under fourteen out of twenty deserves a harder conversation.

What to Read Next

Your next reads

VOCPhone, the Australian-owned cloud phone platform that owns and operates its own network. vocphone.com | 1300 663 222

Related Articles