SoatDev IT Consulting
SoatDev IT Consulting
  • About us
  • Expertise
  • Services
  • How it works
  • Contact Us
  • News
  • July 3, 2024
  • Rss Fetcher
A smartphone sits on top of a surface with red tape reading “DANGER.” Where one strip intersects the phone, it continues inside the phone’s screen.
Photo by Amelia Holowaty Krales / The Verge

Twilio says someone has obtained phone numbers associated with its two-factor authentication service (2FA), Authy, as reported earlier by TechCrunch. In a security alert on Monday, Twilio warns that the “threat actors” may try to use the stolen phone numbers to carry out phishing attacks and other scams.

The incident follows a 2022 data breach that occurred after a phishing campaign tricked employees into disclosing their login credentials. The attackers accessed data from 163 Twilio accounts and managed to access and register additional devices on 93 Authy accounts.

Twilio traced this leak back to “an unauthenticated endpoint” that it has since secured. Last week, the threat actor ShinyHunters published a list of 33 million phone numbers from Authy accounts on the dark web. As pointed out by BleepingComputer, the threat actor seems to have obtained the information by inputting a massive list of phone numbers into Authy’s unsecured API endpoint, which would then verify whether they’re associated with the app.

“We encourage all Authy users to stay diligent and have heightened awareness around the texts they are receiving,” Twilio writes. It adds that it “has seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data” and that Authy accounts weren’t compromised. Twilio is advising users to update their Authy apps on Android and iOS (the Authy desktop app has been discontinued).

Previous Post
Next Post

Recent Posts

  • Y Combinator startup Firecrawl is ready to pay $1M to hire three AI agents as employees
  • Build, don’t bind: Accel’s Sonali De Rycker on Europe’s AI crossroads
  • OpenAI’s planned data center in Abu Dhabi would be bigger than Monaco
  • Google I/O 2025: What to expect, including updates to Gemini and Android 16
  • Thousands of people have embarked on a virtual road trip via Google Street View

Categories

  • Industry News
  • Programming
  • RSS Fetched Articles
  • Uncategorized

Archives

  • May 2025
  • April 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023

Tap into the power of Microservices, MVC Architecture, Cloud, Containers, UML, and Scrum methodologies to bolster your project planning, execution, and application development processes.

Solutions

  • IT Consultation
  • Agile Transformation
  • Software Development
  • DevOps & CI/CD

Regions Covered

  • Montreal
  • New York
  • Paris
  • Mauritius
  • Abidjan
  • Dakar

Subscribe to Newsletter

Join our monthly newsletter subscribers to get the latest news and insights.

© Copyright 2023. All Rights Reserved by Soatdev IT Consulting Inc.