Twilio hack leaves Authy users exposed to text-messaging scams

If you use Authy, update your app immediately. Twilio, the messaging company that owns the two-factor authentication service, confirmed to TechCrunch on Wednesday that hackers breached Twilio and acquired mobile phone numbers for 33 million users.

Twilio published a statement on its website also confirming the hack. “Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint,” the statement reads. “We have taken action to secure this endpoint and no longer allow unauthenticated requests.”

The company added that there was no evidence that the hackers accessed Twilio’s systems or sensitive data. But updating to the latest version of the iOS and Android apps (on any devices you’re running) is critical as they include new security updates.

Twilio stressed that Authy accounts weren’t compromised. However, the hackers (and anyone they share the data with) could “try to use the phone number associated with Authy accounts for phishing and smishing attacks.”

If you aren’t familiar with the term, smishing is the text-message equivalent of phishing. So, if you have an Authy account, be extra cautious about any unexpected texts that appear to come from trusted sources, especially Authy or Twilio.

Rachel Tobac, a social engineering expert and CEO of SocialProof Security, illustrated to TechCrunch what that may look like. “If attackers are able to enumerate a list of user’s phone numbers, then those attackers can pretend to be Authy/Twilio to those users, increasing the believability in a phishing attack to that phone number,” Tobac said.

“We encourage all Authy users to stay diligent and have heightened awareness around the texts they are receiving,” Twilio stressed.

This article originally appeared on Engadget at
Creato 3d | 3 lug 2024, 17:30:27

Accedi per aggiungere un commento

Altri post in questo gruppo

Still Wakes the Deep is a modern horror classic

Don’t look down. Don’t look down. Don’t look down.

Waves the size of skyscrapers explode beneath me as I creep across a busted metal beam in the middle of the North Sea, suspended a

5 lug 2024, 19:30:23 | Engadget
Epic says that Apple rejected its third-party app store for the second time

Epic says that Apple has once again rejected its submission for a third-party app store, according to a seri

5 lug 2024, 19:30:22 | Engadget
The best early Prime Day deals ahead of Amazon's July sale — shop Apple, Anker and more

Amazon Prime Day 2024 is less than two weeks away, but we’re already seeing a handful of decent early de

5 lug 2024, 17:20:09 | Engadget
YouTube film essay pioneers 'Every Frame a Painting' is back

Between 2014 and 2016, a

5 lug 2024, 15:10:13 | Engadget
Amazon takes a new brick-and-mortar approach with a stake in Neiman Marcus

Amazon changed the face of retail over the last 20 years but has failed miserably to make inroads in the luxury goods market. Now, it's trying something new. The online retailer has purchased a sma

5 lug 2024, 15:10:12 | Engadget
YouTube upgrades its 'erase song' tool to remove copyrighted music only

YouTube is trying to make it easy for its creators to remove songs from the

5 lug 2024, 15:10:11 | Engadget
The Morning After: OpenAI’s week of security issues

Perhaps unsurprisingly, July 4th was a quiet day for news, but we’ve still got editorials on e-ink writing, the most-delayed video game ever and

5 lug 2024, 12:40:21 | Engadget