- The American cloud company Twilio revealed that the attack on its authenticator app Authy had compromised the phone numbers of 33 million users.
- Hackers have also been able to identify the accounts linked with those phone numbers.
- A notorious hacker group called ShinyHunters is believed to be behind the attack
Twilio, an American cloud communications company, revealed that a data breach on Authy has left the phone numbers of millions of users exposed.
For those who don’t know, Authy is a two-factor authentication app that provides an additional layer of security on top of your passwords, which is owned by Twilio.
At that time it was unknown whether the hackers could match the numbers with the respective accounts.
ShinyHunters is the same group of hackers that stole the data of 560 million Ticketmaster customers in early June. The 1.3TB of stolen data, which included customers’ phone numbers, names, and addresses, was put up for sale on the dark web for $500,000.
Snowflake, a cloud-storage provider, was also attacked by ShinyHunters affecting millions of customers.
Cause & Impact of the Breach
The cause of the breach is said to be an unauthorized endpoint. Twilio assured that the endpoint has now been secured and no unauthenticated requests are being allowed at the moment.
Now speaking of the impact, it’s important to note that Authy accounts have not been directly compromised. Only the phone numbers have been stolen.
But on the brighter side, Twilio’s internal system and other sensitive data have not been compromised.
There’s nothing much users can do apart from being cautious.
- Do not click on any suspicious links received via text or email.
- Twilio has also requested users to update their Authy app immediately to the latest Android and iOS versions.
Twilio was last hacked in 2022 when a hacker group tricked its employees into sharing their credentials with the help of voice phishing and then accessed the company’s internal systems.
Question & Answers (0)