Security

Twilio says hackers identified cell phone numbers of two-factor app Authy users

Comment

Image Credits: Drew Angerer / Getty Images

Last week, a hacker claimed to have stolen 33 million phone numbers from U.S. messaging giant Twilio. On Tuesday, Twilio confirmed to TechCrunch that “threat actors” were able to identify the phone number of people who use Authy, a popular two-factor authentication app owned by Twilio.

In a post on a well-known hacking forum, the hacker or hackers known as ShinyHunters wrote that they hacked Twilio and obtained the cell phone numbers of 33 million users.

Twilio spokesperson Kari Ramirez told TechCrunch that the company “has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests.”

“We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data. As a precaution, we are requesting all Authy users to update to the latest Android and iOS apps for the latest security updates and encourage all Authy users to stay diligent and have heightened awareness around phishing and smishing attacks,” Ramirez wrote in an email. 

Twilio also published an alert on its official website on Monday, including the same statement. 

Contact Us

Do you have more information about this Twilio/Authy incident? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

While obtaining a list of phone numbers — on its own — may not appear to be the most dangerous of data breaches, it could still pose a threat to the owners of those numbers.

“If attackers are able to enumerate a list of user’s phone numbers, then those attackers can pretend to be Authy/Twilio to those users, increasing the believability in a phishing attack to that phone number,” Rachel Tobac, an expert in social engineering and CEO of SocialProof Security, told TechCrunch.

Tobac explained that now hackers can specifically target people who they know are Authy users, giving the attackers a chance to make it look like their malicious messages really come from Authy and Twilio. 

In 2022, Twilio suffered a larger data breach, when a group of hackers accessed the data of more than 100 company customers. The hackers then launched a wide-ranging phishing campaign which resulted in the theft of around 10,000 employee credentials from at least 130 companies. As part of that breach at the time, Twilio said hackers successfully targeted 93 individual Authy users and were able to register additional devices on those victims’ Authy accounts, allowing them to effectively steal real two-factor codes.

UPDATE, 12:52 p.m. ET: This story has been corrected to clarify that the 2022 Twilio breach is not directly connected to the phishing campaign that resulted in the theft of around 10,000 employee credentials of several companies. The two attacks were allegedly carried out by the same threat actors.

More TechCrunch

A Castro Valley resident was charged Thursday for allegedly slashing the tires of 17 Waymo robotaxis in San Francisco between June 24 and June 26, according to the city’s district…

Waymo cameras capture footage of person charged in alleged robotaxi tire slashings

Featured Article

SoftBank acquires UK AI chipmaker Graphcore

While the figure of $500 million has been bandied around in various reports for months, in a press briefing early Thursday morning, Graphcore co-founder and CEO Nigel Toon remained coy on the details.

SoftBank acquires UK AI chipmaker Graphcore

Elon Musk’s X, formerly Twitter, is continuing to develop a downvoting feature that will be used to improve how replies are ranked. Although the company has not yet officially announced…

X is building a ‘dislike’ button for downvoting replies

Featured Article

Data breach exposes millions of mSpy spyware customers

A huge batch of mSpy customer service emails dating back to 2014 were stolen in a May data breach.

Data breach exposes millions of mSpy spyware customers

Kudos founder says her company makes a disposable diaper lined with 100% cotton, unlike the major competitors.

Shark Tank-backed Kudos raises another $3M for healthier, cotton-based disposable diapers

Astra CEO Chris Kemp is already pulling out of a parking spot when he warns the person in the passenger seat that he doesn’t have a valid driver’s license. “And…

‘Wild Wild Space’ doc captures the risks and rivalries of the new space race

Although these companies’ claims are artfully couched, it’s clear that they want to express that the model sees in some sense of the word.

‘Visual’ AI models might not see anything at all

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Did you…

Lucid revs up sales, Fisker makes a deal and Uber reignites an old fight

Retro CEO Nathan Sharp isn’t worrying just yet about Google’s plan to copy his app’s experience, despite the numerous similarities.

Photo-sharing startup Retro spots Google Photos copying its idea and design

Tesla had internally planned to build the dedicated robotaxi and the $25,000 car, often referred to as the Model 2, on the same platform.

Tesla reportedly delays ‘robotaxi’ event to October

Here’s a look at what’s going to change with Siri, and what the introduction of Apple Intelligence will allow you to do with the digital assistant. 

How Apple Intelligence is changing the way you use Siri on your iPhone 

The new YouTube features include those that will automatically transform longer videos into Shorts, among others.

YouTube tempts creators with a half dozen new features for Shorts

The capital will be used to expand in Europe, the U.S. and Asia.

Exein raised $15M Series B to stop robotic arms going haywire

Last month, the company also started applying an international authentication rate for activities like sending login codes for cross-border users.

WhatsApp now allows businesses to send authentication codes to users in India

Helsing has created a new entity in Estonia and plans to spend €70 million on Baltic defense projects over the next three years.

Defense AI startup Helsing raises $487M Series C, plans Baltic expansion to combat Russian threat

Alma aims to simplify the visa process for technologists, founders and researchers by providing personal legal advisors.

Alma co-founder had such a bad immigration experience she founded a legal AI startup to fix it

WhatsApp Business is changing its per-conversation rates for businesses — a conversation is a 24-hour thread between sellers and users. The company is reducing rates for utility messages and raising…

WhatsApp Business is changing its rates for messages as it aims to reduce marketing spam

HerculesAI (formerly Zero Systems) has been working at automating professional services since 2017, originally concentrating on the legal industry. As part of that, it has actually been building large language…

HerculesAI was working with large language models long before it was cool

DeepMind has implemented Google Gemini 1.5 Pro to teach a robot to respond to commands and navigate around an office.

Watch a robot navigate the Google DeepMind offices using Gemini

What this means for the future of the Fuse line remains unclear, though the companies confirmed with TechCrunch that the Micronics branding is going away.

Formlabs acquires 3D printing startup Micronics mid-Kickstarter campaign

Medal, a startup that is better known for its video game clipping product, just announced that it has raised $13 million at a valuation of $333 million from several investors,…

Medal raises $13M as it builds out a contextual AI assistant for desktop

When early SpaceX engineer Bulent Altan and long-time investor Joram Voelklein surveyed the European space sector at the end of the 2010s, they were surprised: It looked a whole lot…

Alpine Space Ventures closes first fund to grow the space economy on both sides of the pond

People in tech often say that data is the new oil. That phrase, coined by British mathematician Clive Humby, of course implies that data is valuable. Data about a person’s…

AI-powered Regard nabs $61M to find missed illness, boost hospital revenue

Featured Article

Intel Capital backs AI construction startup that could boost Intel’s own manufacturing prospects 

Intel could be giving its burgeoning foundry ambitions a much-needed shot in the arm, as the chip giant’s venture capital arm today revealed that it’s making a “strategic” investment in an Israel- and U.K.-based AI construction startup. Intel Capital is leading a $15 million investment into Buildots, a company that…

Intel Capital backs AI construction startup that could boost Intel’s own manufacturing prospects 

The European Union has accepted commitments from Apple over how it operates Apple Pay to settle a long-running competition investigation. Commission EVP Margrethe Vestager, who heads up the EU’s competition…

EU ends Apple Pay antitrust probe with binding commitments to open up contactless payments

Joby Aviation is still a year away from commercially launching its electric air taxi designed for urban environments, but the startup is already looking toward its next chapter: intercity flight,…

Joby Aviation is betting on hydrogen-electric aircraft for regional flight

Just like in your favorite anime, this is the story of a young group of twentysomethings who started with nothing, traveled the world and ended up with a global license…

Sekai secures Naruto’s license to develop consumer apps for anime fans

Uzbekistan’s mobile-only bank TBC Bank Uzbekistan has raised $38.2 million in a fresh funding by its existing shareholders.

Uzbekistan mobile bank TBC raises $38.2M to expand its financial products

Meet Adfin, a new U.K.-based fintech startup that wants to help companies get their invoices paid — whatever it takes. Founded by two fintech experts, the company is starting with…

Adfin wants to fix bill payments for sole traders and small companies

Reliance Industries, India’s most valuable company, may consider spinning off its telecom arm Jio for a public listing as early as 2025, Jefferies said in a research note, with investors…

Reliance may list Jio at $112B valuation next year, Jefferies says