Thursday, 1 May 2025
26.3 C
Singapore
29.3 C
Thailand
20.3 C
Indonesia
28.6 C
Philippines

A massive security breach: Millions of 2FA codes leaked

Significant security breach where YX International's database leak compromised millions of 2FA codes from major tech firms.

YX International, an Asian tech giant known for its extensive SMS routing services, inadvertently exposed a database containing millions of sensitive text messages. This breach, discovered by security researcher Anurag Sen, compromised the integrity of two-factor authentication (2FA) codes belonging to several major technology companies, including Facebook, Google, and TikTok.

How the breach happened

Imagine a scenario where a database, filled with critical information, is left unguarded on the internet. That’s precisely what happened with YX International. Their internal database, which robust security measures should have shielded, was left open without password protection. This oversight meant anyone with knowledge of the database’s public IP address could access this sensitive data through a web browser.

YX International, a firm boasting the dispatch of 5 million SMS texts daily, failed to secure this database, resulting in a serious security lapse. The database logs, dating back to July 2023, contained one-time passcodes and password reset links for users of some of the world’s most prominent tech firms.

The implications of the leak

You might be wondering how severe this breach is. Two-factor authentication is a widely adopted security measure that sends an additional code to a trusted device, like your phone, to prevent account hijacks. However, the codes found in the leaked database, which are meant to expire after a few minutes or once used, pose a significant risk. The SMS-based 2FA, although convenient, is not as secure as other forms like app-based code generators. This incident highlights the vulnerability of relying on SMS for critical security functions.

When TechCrunch, the news outlet Sen contacted, delved into the exposed database, they discovered the 2FA codes, internal email addresses, and passwords associated with YX International. This breach was reported to the company, leading to the database being offline shortly after that. However, YX International could not confirm the duration the database was exposed or whether any malicious parties accessed the sensitive data.

Tech giant’s response to the breach

Following this discovery, TechCrunch reached out to the affected companies for comments. While a Meta spokesperson chose not to comment, representatives from Google and TikTok did not respond to the requests. YX International acknowledged the vulnerability and claimed to have “sealed” it, yet they could not provide logs to ascertain if others had accessed the data.

This incident is a stark reminder of the fragility of digital security and the importance of robust data protection measures. It highlights the need for continuous vigilance and improvement in cybersecurity protocols for large corporations and all who rely on digital platforms for their daily operations.

Hot this week

Mac-style tools are coming to iOS 19 and iPadOS 19 to boost productivity

Apple is planning Mac-style updates in iOS 19 and iPadOS 19 to boost productivity, with features expected at WWDC 2025.

Apple creates a new celebrity hub to showcase stars across its platforms

Apple has quietly launched a new website to help you explore celebrity content across its TV, Music, and Podcasts apps.

Alibaba reveals Qwen3, a powerful new series of AI models

Alibaba launches Qwen3, a powerful open AI model family with hybrid reasoning and strong performance that rivals Google and Openai.

Snapchat drops plans for simplified app, tests new five-tab layout instead

Snapchat has dropped its simplified app redesign and is testing a new five-tab layout to improve user experience and content discovery.

SquareX secures US$20 million to transform browser security

SquareX raises US$20 million to strengthen browser security, offering enterprises an easy way to protect users without disrupting their workflows.

You can get DOOM: The Dark Ages free with select Nvidia graphics cards

Get DOOM: The Dark Ages Premium Edition free with select Nvidia RTX 50 GPUs until May 21, including in-game extras and early access.

Xiaomi enters China’s AI race with new model to power smart devices

Xiaomi joins China’s AI race with its new MiMo model, aiming to power devices with smarter tech and compete with big tech firms.

Samsung chip profits fall sharply due to US export controls and price drops

Samsung chip profits dropped 40% due to US export rules and price cuts as the company raced to catch up in AI memory production.

Chinese AI and robotics start-ups back Xi’s push for technological self-reliance

Chinese AI and robotics start-ups vow self-reliance after Xi visits Shanghai, showcasing innovation and commitment to homegrown tech.

Related Articles

Popular Categories