Twilio says hackers identified cell phone numbers of two-factor app Authy users

Date:

Share post:


Last week, a hacker claimed to have stolen 33 million phone numbers from U.S. messaging giant Twilio. On Tuesday, Twilio confirmed to TechCrunch that “threat actors” were able to identify the phone number of people who use Authy, a popular two-factor authentication app owned by Twilio.

In a post on a well-known hacking forum, the hacker or hackers known as ShinyHunters wrote that they hacked Twilio and obtained the cell phone numbers of 33 million users.

Twilio spokesperson Kari Ramirez told TechCrunch that the company “has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests.”

“We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data. As a precaution, we are requesting all Authy users to update to the latest Android and iOS apps for the latest security updates and encourage all Authy users to stay diligent and have heightened awareness around phishing and smishing attacks,” Ramirez wrote in an email. 

Twilio also published an alert on its official website on Monday, including the same statement. 

While obtaining a list of phone numbers — on its own — may not appear to be the most dangerous of data breaches, it could still pose a threat to the owners of those numbers.

“If attackers are able to enumerate a list of user’s phone numbers, then those attackers can pretend to be Authy/Twilio to those users, increasing the believability in a phishing attack to that phone number,” Rachel Tobac, an expert in social engineering and CEO of SocialProof Security, told TechCrunch.

Tobac explained that now hackers can specifically target people who they know are Authy users, giving the attackers a chance to make it look like their malicious messages really come from Authy and Twilio. 

In 2022, Twilio suffered a larger data breach, when a group of hackers accessed the data of more than 100 company customers. Armed with that information, the hackers then launched a wide-ranging phishing campaign which resulted in the theft of around 10,000 employee credentials from at least 130 companies. As part of that breach at the time, Twilio said hackers successfully targeted 93 individual Authy users and were able to register additional devices on those victims’ Authy accounts, allowing them to effectively steal real two-factor codes.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Nubank leads $250M round in African digital bank Tyme at $1.5B valuation

Tyme Group, a South African-born fintech operating in the African country and the Philippines, has secured $250...

Mark Zuckerberg says Threads now has 100M daily active users

Meta’s X rival Threads is growing steadily with more than 100 million people using the service daily,...

Waymo robotaxis are coming to Tokyo in 2025

Waymo will begin testing its autonomous vehicle technology in Tokyo in early 2025, the first time the...

Cohere is quietly working with Palantir to deploy its AI models

Cohere is one of the best-known AI startups outside of OpenAI and Anthropic, hitting a $5.5 billion...

Jay-Z’s Marcy Venture Partners merges with investment arm of Pendulum Holdings

Jay-Z’s venture capital firm, Marcy Venture Partners, has merged with another Black-owned investment firm, Pendulum Holdings’ investment...

iRobot co-founder’s new home robot startup hopes to raise $30M

Colin Angle, one of the co-founders of Roomba maker iRobot, is raising cash for a home robotics...

TuSimple’s former CEO wants a new board that will liquidate the company

TuSimple co-founder and former CEO Xiaodi Hou is on a war path in the lead up to...

TikTok asks Supreme Court for a lifeline as sell-or-ban deadline approaches

TikTok and ByteDance asked the United States Supreme Court to block the law that forces TikTok to...