Twilio denied, in a statement to BleepingComputer, that it had been breached, following claims by a cybercriminal that it had over 89 million Steam user records with one-time passwords.
See also: Marks & Spencer: Cyberattack led to data breach

The perpetrator, who uses the alias Machine1337 (also known as EnergyWeaponsUser), was advertising a large set of data supposedly extracted from Steam, offering it for sale for $5,000.
While examining the files, which included 3,000 records, BleepingComputer spotted SMS messages with one-time codes for Steam, including the recipient's phone number.
Steam, owned by Valve Corporation, is the world's largest digital distribution platform for PC games, with over 120 million active users . Valve did not respond to requests for comment on the cybercriminal's claims.
Independent gaming journalist MellowOnline1, who is also the creator of the SteamSentinels that monitors abuse and fraud in the Steam ecosystem, believes this is a supply chaininvolving Twilio.
See also: 437,000 affected by Ascension Health breach
MellowOnline1 pointed out technical elements within the data, which appear to include real-time SMS logs from Twilio's back-end systems, suggesting a possible administrator account breach or API key.

Twilio is a cloud communications company that provides APIs for sending SMS, voice calls, and two-factor authentication (2FA) messages and is widely used by apps like Steam to authenticate users. Twilio later issued a clarification, stressing that the company's systems were not breached.
Looking at the data, one possible explanation for its origin is a leak from an SMS provider that acts as an intermediary for communicating one-time passwords between Twilio and Steam users.
Some of the messages delivered clearly appear to be verification codes for accessing a Steam account or linking a phone number to it. Twilio offers a two-factor authentication product called Verify API, which customers – including game providers – can integrate through various communication channels (SMS, WhatsApp, voice calls, email, passkeys, silent device verification, push notifications, or time-based one-time codes).
See also: Ledger secures Discord server after moderator account hack
Based on the above, the incident seems to highlight the risks associated with the supply chain in digital services, especially when third-party providers like Twilio are involved for critical security functions, such as sending 2FA codes. Even if Twilio insists that its own systems were not compromised, the possibility of a leak through an intermediary SMS provider shows that even a seemingly secure infrastructure can be vulnerable if any part of the chain is compromised.
Source: bleepingcomputer
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
