Authy Alert: Millions of Phone Numbers Exposed in API Blunder, Users Urged to Update Apps

Twilio confirms an unsecured API exposed millions of Authy users’ phone numbers, making them vulnerable to SMS phishing and SIM swapping attacks. The issue has been fixed, but users should update their apps and stay vigilant.

Pro Dashboard

Hot Take:

Wow, Twilio, you had one job! It’s like leaving the front door wide open and wondering why the living room is full of raccoons. Time to double down on securing those API endpoints before the entire zoo gets in!

Key Points:

  • Unsecured API endpoint exposed phone numbers of millions of Authy users.
  • Threat actor ShinyHunters leaked a CSV file with over 33 million phone numbers.
  • Twilio confirms the endpoint has been secured; no evidence of access to other sensitive data.
  • Users are urged to update their Authy apps and stay vigilant against phishing and smishing attacks.
  • Securing mobile accounts is crucial to prevent SIM swapping and other types of attacks.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?