HomeSecurityTwilio: Hackers verified Authy users' phone numbers via API

Twilio: Hackers verified Authy users' phone numbers via API

Twilio has confirmed that an insecure API endpoint allowed cybercriminals to verify the phone numbers of millions users of Authy MFA , leaving them vulnerable to SMS phishing and SIM swapping attacks .

Twilio Authy phone numbers

Authy is a mobile app that generates multi-factor authentication codes for accessing sites.

In late June, hackers ShinyHunters leaked a CSV text file that they claimed contained 33 million phone numbers registered with the Authy service. The CSV file contains 33,420,546 rows, each containing an account ID, a phone number, an “over_the_top” column, the account status, and the number of devices.

See also: Mercku support portal sends MetaMask phishing emails

Twilio confirmed that the attackers created the list of numbers using an unauthenticated API endpoint. Twilio has taken steps to secure this endpoint, preventing unauthorized requests.

“We have not seen any evidence that threat gained access to Twilio’s systems or other sensitive data. As a precaution, we are asking all Authy users to get the latest updates to their Android and iOS apps and encourage all Authy users to remain vigilant for phishing and smishing attacks.”

Abuse of unsafe APIs

BleepingComputer learned that the data was collected by feeding a huge list of phone to the insecure API endpoint. If the number was valid, the endpoint would return information about the associated accounts registered with Authy.

Now that the API has been secured, it can no longer be abused to verify numbers.

See also: New “military-themed” phishing campaign targets Pakistan

Twilio has released a new security update and recommends that users upgrade to Authy Android (v25.1.0) and iOS App (v26.1.0). It is unclear how this security update helps protect users from threat actors who can use the compromised data in attacks.

Twilio: Hackers verified Authy users' phone numbers via API

Authy users should also ensure that their mobile accounts are configured to block number porting without providing a password or disabling security protections.

Additionally, Authy users should be on the lookout for potential phishing SMS This breach could have serious implications for user security, as attackers could gain access to sensitive accounts and data. Users who rely on SMS for identity verification should consider switching to more secure methods, such as authenticator apps or physical security devices.

See also: Quishing: Phishing emails with QR codes target Chinese people

As previously stated, Twilio has already taken steps to patch the vulnerability and notify users of the potential threat. However, users should remain vigilant for suspicious activity on accounts and update their security measures to protect themselves from future attacks.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS