Friday, 7 March 2025
27.5 C
Singapore
28.4 C
Thailand
24 C
Indonesia
26.9 C
Philippines

Twilio detects unauthorised access to Authy accounts, urges updates to prevent phishing attacks

Twilio detects unauthorised access to Authy accounts, urging updates and vigilance against phishing attacks

Last week, Twilio, the company behind the two-factor authentication (2FA) app Authy, confirmed that unauthorised access may have exposed Authy users’ phone numbers. This incident has raised concerns among users of the popular app.

How did the incident happen?

Twilio revealed in a security alert that the unauthorised access was due to an unauthenticated endpoint in their system. This vulnerability allowed the ShinyHunters group to input phone numbers and verify whether they were linked to Authy accounts, exposing 33 million phone numbers.

The company has since secured the endpoint, preventing any further unauthenticated access. Twilio reassured users that there is no evidence that unauthorised actors accessed other sensitive data or the company’s systems beyond these phone numbers.

Twilio’s response and recommendations

Given this incident, Twilio strongly advises all Authy users to update their Android and iOS apps to the latest versions. These updates include enhanced security measures to protect against potential threats. Twilio also warns that the stolen phone numbers could be used for phishing (fraudulent emails) and smishing (fraudulent text messages) attacks. Therefore, users should remain vigilant and cautious about any suspicious communications.

This is not the first time Twilio has faced a security incident. Two years ago, unauthorised actors successfully phished several employees to access data from over 100 Twilio customers. This previous incident highlights the ongoing challenge of securing digital platforms against increasingly sophisticated cyber threats.

Protecting yourself from future attacks

Twilio’s latest security incident underscores the importance of staying updated with the newest app versions and being aware of potential phishing and smishing attempts. Users should regularly check for updates and apply them promptly to protect their accounts. Additionally, being cautious about unsolicited messages and verifying the authenticity of communications can help prevent falling victim to these attacks.

Twilio continues improving its security measures to protect its users and prevent future incidents. Taking proactive steps and staying informed can better safeguard your personal information against cyber threats.

Editor’s note: This story has been updated with a response from Twilio. Twilio has seen no evidence that the threat actors breached its systems or obtained access to its systems or other sensitive internal data. As a precaution, Twilio is requesting all Authy users to update to the latest Android and iOS apps for the latest security updates and encourages all Authy users to stay diligent and maintain heightened awareness around phishing and smishing attacks.

Hot this week

Security breach detected in Zapier’s code repositories

Zapier confirmed a security breach that exposed customer data after unauthorized access to its code repositories. Here's what you need to know.

Samsung Galaxy S25 Ultra review: Redefining mobile innovation with AI

The Samsung Galaxy S25 Ultra combines powerful performance, advanced AI features, and a stunning camera system in a sleek design, offering an exceptional smartphone experience.

OpenAI plans to integrate Sora into ChatGPT

OpenAI plans to integrate its AI video tool, Sora, into the ChatGPT app alongside new features like GPT-4.5 and the Operator tool.

Microsoft to shut down Skype in May and focus on Teams

Microsoft will shut down Skype on May 5 and focus on Teams. Users can transfer their chats and contacts to Teams for a seamless switch.

Salesforce launches Agentforce 2dx to embed proactive AI into business workflows

Salesforce launches Agentforce 2dx, letting businesses add proactive AI agents into workflows to boost automation and efficiency.

ROG Astral GeForce RTX 5090 OC Edition sets six overclocking records

ASUS ROG Astral GeForce RTX 5090 OC Edition breaks six overclocking records in global benchmark tests with advanced cooling and boosted clock speeds.

Crunchyroll announces cinema release dates for Demon Slayer: Kimetsu no Yaiba Infinity Castle

Crunchyroll announces cinema release dates for Demon Slayer: Kimetsu no Yaiba Infinity Castle, starting 14 August 2025 in Singapore and Malaysia.

Trump proposes US crypto reserve, raising concerns over economic impact

Trump proposes a US Crypto Reserve, raising concerns about its impact on the economy and the dollar. Could this move benefit crypto donors over taxpayers?

Apple unveils MacBook Air with M4 chip, new Sky Blue colour, and lower prices

Apple unveils the MacBook Air with the M4 chip, a Sky Blue colour, and lower prices. Pre-orders are open now, and retail availability will be on March 12.

Related Articles