Twilio Customer Data Exposed after its Staffers got Phished

R2D2

Level 6
Verified
Well-known
Aug 7, 2017
267
Thanks @Lament are the trackers a recent discovery? Do you have a link where I could read more on this topic, please?

BTW I am using 2FAS on Android and iOS. Aegis on Android works very well too but 2FAS is just a backup app. I simply can't afford to have my TOTP tied down to a single mobile device, like Google Authenticator et al do, just in case of damage or loss. I'd been in deep trouble if I were to lose my TOTP device. The recovery process for scores of accounts with 2FA enabled would be a collective nightmare.
 

upnorth

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 27, 2015
5,459
The fallout from this month's breach of security provider Twilio keeps coming. Three new companies—authentication service Authy, password manager LastPass, and food delivery service DoorDash—said in recent days that the Twilio compromise led to them being hacked.

The three companies join authentication service Okta and secure messenger provider Signal in the dubious club of Twilio customers known to be breached in follow-on attacks that leveraged the data obtained by the intruders. In all, security firm Group-IB said on Thursday, at least 136 companies were similarly hacked, so it's likely many more victims will be announced in the coming days and weeks.

 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top