Authy Alert: Millions of Phone Numbers Exposed in API Blunder, Users Urged to Update Apps

Twilio confirms an unsecured API exposed millions of Authy users’ phone numbers, making them vulnerable to SMS phishing and SIM swapping attacks. The issue has been fixed, but users should update their apps and stay vigilant.

Hot Take:

Wow, Twilio, you had one job! It’s like leaving the front door wide open and wondering why the living room is full of raccoons. Time to double down on securing those API endpoints before the entire zoo gets in!

Key Points:

  • Unsecured API endpoint exposed phone numbers of millions of Authy users.
  • Threat actor ShinyHunters leaked a CSV file with over 33 million phone numbers.
  • Twilio confirms the endpoint has been secured; no evidence of access to other sensitive data.
  • Users are urged to update their Authy apps and stay vigilant against phishing and smishing attacks.
  • Securing mobile accounts is crucial to prevent SIM swapping and other types of attacks.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here