---
title: "Kurt Got Got"
url: https://daily.dev/posts/kurt-got-got-zhrtqb70a
source_url: https://fly.io/blog/kurt-got-got/
type: article
source: "Fly.io"
published: 2025-10-08T21:06:18.567Z
updated: 2025-10-08T21:06:43.078Z
tags: ["security", "authentication", "phishing"]
reading_time: 6
upvotes: 3
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Kurt Got Got

**[Fly.io](https://daily.dev/sources/flydotio)** · 6 min read · 3 upvotes · 0 comments

## Summary

Fly.io's CEO fell victim to a sophisticated phishing attack that compromised their Twitter account for 15 hours. The attacker exploited psychological vulnerabilities by sending a fake alert about a questionable post, prompting the CEO to log in through a fake domain. The incident highlights why phishing-resistant authentication (like FIDO2 and Passkeys) is essential, as training alone cannot prevent all phishing attempts. The company's infrastructure remained secure because it uses SSO with phishing-proof MFA, but their Twitter account was a legacy shared credential managed through 1Password. The attack resulted in a crypto scam post and temporary brand damage, but no user data was compromised.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://fly.io/blog/kurt-got-got/>

## Similar posts on daily.dev

- [I fell for a phishing attack and lost access to my X account. Here are five mistakes I did that you need to avoid\!](https://daily.dev/posts/i-fell-for-a-phishing-attack-and-lost-access-to-my-x-account-here-are-five-mistakes-i-did-that-you--cfsxn3pdx) · Christian Heilmann · 7 upvotes · 2 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/kurt-got-got-zhrtqb70a)
