Twilio, the parent company of the popular two-factor authentication app Authy, has confirmed a significant security breach.
The incident has exposed the phone numbers of 33 million Authy users.
A hacker claimed to have acquired 33 million Authy users’ phone numbers last week.
Twilio has now verified this claim, stating “Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests. We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data.”
Twilio has secured the vulnerable endpoint and no longer allows unauthenticated requests.
The company is advising all Authy users to update to the latest Android and iOS app versions for improved security.
“If attackers are able to enumerate a list of user’s phone numbers, then those attackers can pretend to be Authy/Twilio to those users, increasing the believability in a phishing attack to that phone number,” Rachel Tobac, an expert in social engineering and CEO of SocialProof Security, told TechCrunch.
Authy users should:
1. Update their Authy app immediately
2. Be vigilant against potential phishing attempts using the exposed phone numbers
3. Consider migrating to alternative authenticator apps like Google Authenticator
Authy is widely used for generating two-factor authentication codes for various services including Twitter, Instagram, and Google accounts.
While the breach doesn’t directly compromise these codes, it raises concerns about the overall security of the platform.
Users are advised to remain cautious about any unexpected communications they receive, especially those requesting sensitive information or authentication details.
This incident serves as a reminder of the importance of regularly updating security apps and being prepared to switch to alternative solutions when necessary.
The breach exposed the phone numbers of 33 million Authy users due to an unauthenticated endpoint.
Yes, Twilio has secured the vulnerable endpoint and no longer allows unauthenticated requests.
Authy users should update their app immediately, be vigilant against phishing attempts, and consider alternative authenticator apps.
While the codes themselves are not compromised, the breach raises concerns about the overall security of the platform.
Users should regularly update security apps, be cautious of unexpected communications, and be prepared to switch to alternative solutions if necessary.
Also Read: How to Download Aadhaar, PAN card on Your WhatsApp
Also Read: PAN Card Online Apply: How to Apply for PAN Card Online, Check Status, and Download e-PAN?
Highlights Haier Appliances India launches Spartan AI Tower AC with AI-Atmox for intelligent, personalised cooling.…
Highlights Samsung India launches Finance+ schemes with EMIs starting at just Rs 33 per day.…
Highlights Vivo has launched the Y500s, which comes with a large 7,200mAh battery and a…
Highlights Upcoming Realme phone tipped to feature a 165Hz flat OLED display and a 9,000mAh…
Highlights Dell Technologies has launched the XPS 14 and XPS 16 laptops in India, calling…
Highlights Redmi Headphones Neo leak confirms 40mm titanium drivers, 42dB ANC, Bluetooth 5.4, and up…
This website uses cookies.