Millions Of Phone Numbers Exposed In Twilio’s Authy App Breach

U.S. messaging giant Twilio on Monday disclosed a data breach that has allowed threat actors to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint.

The company said that has taken action to secure this endpoint to no longer allow unauthenticated requests.

For those unaware, Twilio is the developer behind the popular two-factor authentication (2FA) app Authy, which was acquired by the company in 2015.

It is a free mobile app that generates multi-factor authentication (MFA) codes at websites where you have MFA enabled.

The disclosure from Twilio comes after a hacker known as ShinyHunters claimed in a post on BreachForums last week to have stolen 33 million phone numbers reportedly from Authy accounts.

“We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data,” Twilio wrote in a security alert published on Monday.

Although Authy accounts were not compromised, there are chances that the threat actors may try to use the phone number associated with Authy accounts, making them likely vulnerable to SMS phishing and SIM swapping attacks, it added.

“We encourage all Authy users to stay diligent and have heightened awareness around the texts they are receiving,” Twilio emphasized.

As a precautionary measure, the company is requesting all Authy users to download the latest version of Android (version 25.1.0 or later) and iOS (version 26.1.0 or later) apps, as they address bug fixes, which include security updates.

Those who are unable to access their Authy account are requested to contact Authy support immediately for assistance in getting their account back up and running again.

“We know the security of our systems is an important part of earning and keeping your trust. We sincerely apologize that this happened,” the company concluded.

Subscribe to our newsletter

To be updated with all the latest news

Kavita Iyer
Kavita Iyer
An individual, optimist, homemaker, foodie, a die hard cricket fan and most importantly one who believes in Being Human!!!


Please enter your comment!
Please enter your name here

Subscribe to our newsletter

To be updated with all the latest news

Read More

Suggested Post