{"id":109393,"date":"2024-07-03T21:10:10","date_gmt":"2024-07-03T21:10:10","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/07\/03\/twilio-alerts-authy-two-factor-app-users-that-threat-actors-have-their-phone-numbers\/"},"modified":"2024-07-03T21:10:10","modified_gmt":"2024-07-03T21:10:10","slug":"twilio-alerts-authy-two-factor-app-users-that-threat-actors-have-their-phone-numbers","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/07\/03\/twilio-alerts-authy-two-factor-app-users-that-threat-actors-have-their-phone-numbers\/","title":{"rendered":"Twilio alerts Authy two-factor app users that \u201cthreat actors\u201d have their phone numbers"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Twilio says someone has obtained phone numbers associated with its two-factor authentication service (2FA), Authy, as <a href=\"https:\/\/techcrunch.com\/2024\/07\/03\/twilio-says-hackers-identified-cell-phone-numbers-of-two-factor-app-authy-users\/\" target=\"_blank\" rel=\"noopener\">reported earlier by <em>TechCrunch<\/em><\/a>. In a <a href=\"https:\/\/www.twilio.com\/en-us\/changelog\/Security_Alert_Authy_App_Android_iOS\" target=\"_blank\" rel=\"noopener\">security alert<\/a> on Monday, Twilio warns that the \u201cthreat actors\u201d may try to use the stolen phone numbers to carry out phishing attacks and other scams.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">The incident follows a 2022 <a href=\"https:\/\/www.theverge.com\/2022\/8\/8\/23296923\/twilio-data-breach-phishing-campaign-employees-targeted\" target=\"_blank\" rel=\"noopener\">data breach<\/a> that occurred after a phishing campaign tricked employees into disclosing their login credentials. The <a href=\"https:\/\/www.theverge.com\/2022\/8\/26\/23323036\/phishing-scam-campaign-twilio-hack-companies\" target=\"_blank\" rel=\"noopener\">attackers accessed data<\/a> from 163 Twilio accounts and managed to access and register additional devices on 93 Authy accounts.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">Twilio traced this leak back to \u201can unauthenticated endpoint\u201d that it has since secured. Last week, the threat actor ShinyHunters <a href=\"https:\/\/x.com\/DarkWebInformer\/status\/1806436700870287682\" target=\"_blank\">published a list<\/a> of 33 million phone numbers from Authy accounts on the dark web. As <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers\/\" target=\"_blank\" rel=\"noopener\">pointed out by <em>BleepingComputer<\/em><\/a>, the threat actor seems to have obtained the information by inputting a massive list of phone numbers into Authy\u2019s unsecured API endpoint, which would then verify whether they\u2019re associated with the app.<\/p>\n<\/div>\n<div class=\"duet--article--article-body-component\">\n<p class=\"duet--article--dangerously-set-cms-markup duet--article--standard-paragraph mb-20 font-fkroman text-18 leading-160 -tracking-1 selection:bg-franklin-20 dark:text-white dark:selection:bg-blurple [&amp;_a:hover]:shadow-highlight-franklin dark:[&amp;_a:hover]:shadow-highlight-blurple [&amp;_a]:shadow-underline-black dark:[&amp;_a]:shadow-underline-white\">\u201cWe encourage all Authy users to stay diligent and have heightened awareness around the texts they are receiving,\u201d Twilio writes. It adds that it \u201chas seen no evidence that the threat actors obtained access to Twilio\u2019s systems or other sensitive data\u201d and that Authy accounts weren\u2019t compromised. Twilio is advising users to update their Authy apps on Android and iOS (the <a href=\"https:\/\/help.twilio.com\/articles\/22771146070299\" target=\"_blank\" rel=\"noopener\">Authy desktop app has been discontinued<\/a>).<\/p>\n<\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.theverge.com\/2024\/7\/3\/24191791\/twilio-authy-2fa-app-phone-numbers-hack-data-breach\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Twilio says someone has obtained phone numbers associated with its two-factor authentication service (2FA), Authy, as reported earlier by TechCrunch. In a security alert on Monday, Twilio warns that the \u201cthreat actors\u201d may try to use the stolen phone numbers to carry out phishing attacks and other scams. The incident follows a 2022 data breach [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":109394,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-109393","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/109393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=109393"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/109393\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/109394"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=109393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=109393"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=109393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}