Security News Hackers abused API to verify millions of Authy MFA phone numbers

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,680
Twilio has confirmed that an unsecured API endpoint allowed threat actors to verify the phone numbers of millions of Authy multi-factor authentication users, potentially making them vulnerable to SMS phishing and SIM swapping attacks.

Authy is a mobile app that generates multi-factor authentication codes at websites where you have MFA enabled.

In late June, a threat actor named ShinyHunters leaked a CSV text file containing what they claim are 33 million phone numbers registered with the Authy service.

The CSV file contains 33,420,546 rows, each containing an account ID, phone number, an "over_the_top" column, account status, and device count.

Twilio has now confirmed to BleepingComputer that the threat actors compiled the list of phone numbers using an unauthenticated API endpoint.

"Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests," Twilio told BleepingComputer.

"We have seen no evidence that the threat actors obtained access to Twilio's systems or other sensitive data. As a precaution, we are requesting all Authy users to update to the latest Android and iOS apps for the latest security updates and encourage all Authy users to stay diligent and have heightened awareness around phishing and smishing attacks."
 

gonza

Level 2
Sep 10, 2019
67
I used Authy for years until 2 weeks ago. Because they locked me out after resetting my phone.

I moved all my codes to 2fas and then deleted my Authy account. Reading this, I'm glad that Authy locked me out that day.
 

SpiderWeb

Level 13
Verified
Top Poster
Well-known
Aug 21, 2020
610
Everybody has been warned for years of the dangers of using a cloud based 2fa app. Always store them offline for this very reason.
 
  • Like
Reactions: gonza

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top