logo

Twilio denies breach following leak of alleged Steam 2FA codes

ID: 786dcf0d-2e3d-595c-b59b-14a224067b1e

STIX ID: report--786dcf0d-2e3d-595c-b59b-14a224067b1e

Feed Name: Bleeping Computer

Threat Score
45/100

Date Published: 2025-05-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A threat actor claimed to possess and offered for sale a trove of Steam one-time SMS authentication codes (allegedly 89 million records); BleepingComputer reviewed a 3,000-record sample that included historic SMS codes and phone numbers. Twilio and Steam have denied breaches of their systems, and analysis suggests the data may have originated from an intermediary SMS provider or from abused credentials rather than a direct compromise of Twilio or Steam; the dataset contains some recent entries but whether the records are exploitable remains unverified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.