logo

Hackers abused API to verify millions of Authy MFA phone numbers

ID: fa793726-5ceb-5cc4-9929-08fdcd4f6c57

STIX ID: report--fa793726-5ceb-5cc4-9929-08fdcd4f6c57

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-07-03

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Twilio confirmed that an unauthenticated Authy API endpoint was abused to verify and compile ~33.42 million Authy-registered phone numbers, which were later leaked by the threat actor ShinyHunters; Twilio has secured the endpoint and released Authy app updates, advising users to be vigilant about smishing and SIM-swap attempts, and there is no reported evidence of broader system compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.