Authy Users Urged to Stay Alert After 33 Million Phone Numbers Exposed

Twilio has updated its Authy two-factor authentication (2FA) service after a hacker claimed to have retrieved 33 million phone numbers from its user database.

authy
TechCrunch reports that the hacker(s) known as ShinyHunters took to a well-known hacking forum to boast about the theft of 33 million cell phone numbers, achieved by what Twilio described as the use of an "authenticated endpoint."

The U.S. messaging giant confirmed this week that "threat actors" gained access to its servers, resulting in the theft of users' phone numbers, but it did not specify how many were accessed. The company said it had taken action to secure the exploit and prevent similar future unauthenticated requests.

"We have seen no evidence that the threat actors obtained access to Twilio's systems or other sensitive data," said the company in a blog post. "While Authy accounts are not compromised, threat actors may try to use the phone number associated with Authy accounts for phishing and smishing attacks; we encourage all Authy users to stay diligent and have heightened awareness around the texts they are receiving."

As Twilio notes, obtaining a list of phone numbers may not appear in itself to pose a severe security threat. However, attackers could conceivably contact users and claim to be Authy or Twilio representatives in order to get them to reveal personal information as part of a phishing campaign.

Users should update to the latest version of the iOS app, available on the App Store. Twilio also advises users who cannot access their Authy account to contact its support team immediately.

At the beginning of the year, Authy announced that it was shutting down its Mac and Linux desktop apps in August 2024, but ended up bringing the date forward. The apps were subsequently killed off in March.

Popular Stories

apple wallet drivers license feature iPhone 15 pro

Apple Plans to Expand iPhone Driver's Licenses to These 7 U.S. States

Thursday January 2, 2025 6:45 am PST by
In select U.S. states, residents can add their driver's license or state ID to the Wallet app on the iPhone and Apple Watch, providing a convenient and contactless way to display proof of identity or age at select airports and businesses, and in select apps. Below, we outline which U.S. states and territories offer the feature, and additional states that have committed to rolling it out in...
MacBook Air 15 Inch Feature Purple

New MacBook Air Models Coming Soon With These Rumored Features

Thursday January 2, 2025 6:42 am PST by
One of Apple's first product announcements of 2025 will likely be updated 13-inch and 15-inch MacBook Air models with the M4 chip. Below, we recap rumors about the next MacBook Air models. New Features Expected The new MacBook Air models are expected to be equipped with Apple's already-released M4 chip, which has a 10-core CPU and a 10-core GPU. Apple already updated the MacBook...
iPhone 17 Slim Feature Single Camera 1 Redux

iPhone 17 Air's Thickness and Price Range Revealed in New Report

Friday January 3, 2025 7:16 am PST by
Apple is widely rumored to be planning an ultra-thin iPhone 17 model for release later this year, and a new report offers a few purported details. South Korea's Sisa Journal today reported that Apple is aiming for the so-called "iPhone 17 Air" to be 6.25mm thick. If that measurement ends up being accurate, the device would become the thinnest iPhone ever, topping the current 6.9mm record set ...
apple vision pro

Apple Vision Pro May Now Be Out of Production

Tuesday December 31, 2024 2:00 pm PST by
Apple's first-generation Vision Pro headset may have now ceased production, following reports of reduced demand and production cuts earlier in the year. In October, The Information's Wayne Ma reported that Apple had abruptly reduced production of the Vision Pro headset ahead of potential plans to stop making the current version of the device completely by the end of 2024. With the year now...
iPhone SE 4 Thumb 1

'iPhone SE 4' Rumored to Be Named 'iPhone 16E'

Wednesday January 1, 2025 8:31 am PST by
Apple is expected to release a fourth-generation iPhone SE in March, but it has been rumored that the device will have a different name. The device succeeding the third-generation iPhone SE will be named the iPhone 16E, according to a December 13 post from Fixed Focus Digital, an account with over two million followers on Chinese social media platform Weibo. On December 31, another leaker...
aapl logo banner

Apple Broke a 13-Year Hardware Streak in 2024

Wednesday January 1, 2025 1:00 am PST by
For over a decade, Apple has consistently announced all-new hardware product lines, from the iPad in 2010 to the Vision Pro in 2023. But for the first time in 14 years, Apple failed to announce any major new hardware products in 2024, focusing solely on updates and refinements to its existing product lines. While Apple unveiled a large number of significant hardware refreshes in 2024, such...
Generic iOS 18

Here's What's New in iOS 18.3 So Far

Friday January 3, 2025 11:58 am PST by
iOS 18.3 is currently in beta for developers and public beta testers. So far, the upcoming iPhone software update is very minor in scope. Below, we outline what is new in iOS 18.3 so far. The only potential new feature coming to iPhones with iOS 18.3 so far is robot vacuum support in the Home app, but this functionality is not yet live. Apple is laying the groundwork for the feature,...
Tim Cook MacBook

Apple CEO Tim Cook Donating $1 Million to Trump's Inaugural Fund

Friday January 3, 2025 1:27 pm PST by
Apple CEO Tim Cook plans to donate $1 million to Donald Trump's inauguration fund, reports Axios. The donation will be a personal donation directly from Cook rather than a donation from Apple. Following Trump's win, Cook congratulated him on social media site X, and in December, Cook had dinner with Trump at Mar-a-Lago. Cook aimed to maintain a relationship with Trump during Trump's first...

Top Rated Comments

jasonsmith_88 Avatar
26 weeks ago
Been using Authy for years but I’ve always been suss on the requirement for a phone number, especially as Twilio’s entire business model is SMS.

You should not have to, nor expect to, disclose your phone number in order to use a TOTP generator. My data has already been leaked so many times, so I migrated to 2FAS about a month ago in anticipation of an event like this. Sadly my data was leaked because Authy takes 30 days to delete an account ?

Do not use Authy.
Score: 14 Votes (Like | Disagree)
antiprotest Avatar
26 weeks ago

Never even heard of Twilio, should we be concerned? :rolleyes:
Many of the services you have heard of use Twilio. It offers APIs and such. So it's not a name customers will always directly face, but it's there. In this case, Twilio owns Authy.
Score: 10 Votes (Like | Disagree)
JosephAW Avatar
26 weeks ago
Never even heard of Twilio, should we be concerned? :rolleyes:
Score: 7 Votes (Like | Disagree)
chucker23n1 Avatar
26 weeks ago

Many of the services you have heard of use Twilio.
Yep.

For example, lots of companies use Twilio SendGrid for transactional mails (password change confirmations, etc.) or marketing mails (newsletters, etc.). Or they use Twilio itself to send text messages.
Score: 6 Votes (Like | Disagree)
WarmWinterHat Avatar
26 weeks ago

Bummer. I liked Twilio's Authy, in part because it synced well between macOS and iOS. But now iCloud Keychain can do this as well, so I might as well migrate to that.

I also still use Twilio's SendGrid.
I don't use Authy anymore, but I've always kept my 2FA codes separate from my passwords app. If one got compromised, at least the 2FA sites would still be secure.
Score: 6 Votes (Like | Disagree)
Jackbequickly Avatar
26 weeks ago
Things like this happen all the time. Most of the time we never are even informed, even when they get way more than our phone numbers. It is near unavoidable in today's world.
Score: 5 Votes (Like | Disagree)