Authy phone numbers accessed by cybercriminals, warns Twilio
ID: 100059ca-74a6-5596-983a-3ca01949dbc6
STIX ID: report--100059ca-74a6-5596-983a-3ca01949dbc6
Feed Name: Malwarebytes Blog
Threat Score
Twilio warned that an unsecured Authy API endpoint was abused to verify phone numbers for millions of users; a threat actor (ShinyHunters) later posted a CSV claiming ~33 million Authy phone numbers. While Twilio reports no evidence of internal system compromise, the exposed numbers increase risk of SIM-swap and phishing attacks, and users are advised to update Authy and monitor for suspicious messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
