Monday, 20 October 2025
29.1 C
Singapore
25.9 C
Thailand
21.7 C
Indonesia
29 C
Philippines

A massive security breach: Millions of 2FA codes leaked

Significant security breach where YX International's database leak compromised millions of 2FA codes from major tech firms.

YX International, an Asian tech giant known for its extensive SMS routing services, inadvertently exposed a database containing millions of sensitive text messages. This breach, discovered by security researcher Anurag Sen, compromised the integrity of two-factor authentication (2FA) codes belonging to several major technology companies, including Facebook, Google, and TikTok.

How the breach happened

Imagine a scenario where a database, filled with critical information, is left unguarded on the internet. That’s precisely what happened with YX International. Their internal database, which robust security measures should have shielded, was left open without password protection. This oversight meant anyone with knowledge of the database’s public IP address could access this sensitive data through a web browser.

YX International, a firm boasting the dispatch of 5 million SMS texts daily, failed to secure this database, resulting in a serious security lapse. The database logs, dating back to July 2023, contained one-time passcodes and password reset links for users of some of the world’s most prominent tech firms.

The implications of the leak

You might be wondering how severe this breach is. Two-factor authentication is a widely adopted security measure that sends an additional code to a trusted device, like your phone, to prevent account hijacks. However, the codes found in the leaked database, which are meant to expire after a few minutes or once used, pose a significant risk. The SMS-based 2FA, although convenient, is not as secure as other forms like app-based code generators. This incident highlights the vulnerability of relying on SMS for critical security functions.

When TechCrunch, the news outlet Sen contacted, delved into the exposed database, they discovered the 2FA codes, internal email addresses, and passwords associated with YX International. This breach was reported to the company, leading to the database being offline shortly after that. However, YX International could not confirm the duration the database was exposed or whether any malicious parties accessed the sensitive data.

Tech giant’s response to the breach

Following this discovery, TechCrunch reached out to the affected companies for comments. While a Meta spokesperson chose not to comment, representatives from Google and TikTok did not respond to the requests. YX International acknowledged the vulnerability and claimed to have “sealed” it, yet they could not provide logs to ascertain if others had accessed the data.

This incident is a stark reminder of the fragility of digital security and the importance of robust data protection measures. It highlights the need for continuous vigilance and improvement in cybersecurity protocols for large corporations and all who rely on digital platforms for their daily operations.

Hot this week

Pixel 10 Pro Fold review: Google’s most polished and capable foldable yet

The Pixel 10 Pro Fold combines premium design, powerful AI, strong performance and advanced cameras in Google’s most refined foldable yet.

ASUS wins 15 accolades at Good Design Awards 2025

ASUS secures 15 wins at the Good Design Awards 2025, leading Taiwan and the ICT category with innovative, user-focused products.

Samsung partners with Nvidia to develop custom CPUs and XPUs for AI dominance

Nvidia partners with Samsung to develop custom CPUs and XPUs, expanding its NVLink Fusion ecosystem to strengthen its AI hardware dominance.

Salesforce and OpenAI join forces to transform enterprise work and commerce

Salesforce and OpenAI are partnering to integrate frontier AI and CRM tools, transforming enterprise workflows and conversational commerce.

Veeam launches new data cloud platform for managed service providers

Veeam launches Data Cloud for MSPs, a new SaaS platform that simplifies data resilience, strengthens security, and helps providers scale services.

Shadow of the Colossus turns 20: Exploring the moral depth of gaming’s quietest hero

Shadow of the Colossus marks its 20th anniversary, celebrated for its quiet heroism, moral depth, and enduring emotional power.

Samsung partners with Nvidia to develop custom CPUs and XPUs for AI dominance

Nvidia partners with Samsung to develop custom CPUs and XPUs, expanding its NVLink Fusion ecosystem to strengthen its AI hardware dominance.

NVIDIA unveils first US-made Blackwell wafer as domestic chip production expands

NVIDIA unveils its first US-made Blackwell wafer at TSMC’s Arizona facility, marking a major milestone in domestic AI chip production.

8BitDo unveils NES40 collection to mark 40 years of the Nintendo Entertainment System

8BitDo marks 40 years of the NES with a limited NES40 collection featuring redesigned controllers, a premium keyboard, and a modernised speaker.

Related Articles