Saturday, 18 October 2025
26.4 C
Singapore
27.2 C
Thailand
20.3 C
Indonesia
27.7 C
Philippines

Twilio detects unauthorised access to Authy accounts, urges updates to prevent phishing attacks

Twilio detects unauthorised access to Authy accounts, urging updates and vigilance against phishing attacks

Last week, Twilio, the company behind the two-factor authentication (2FA) app Authy, confirmed that unauthorised access may have exposed Authy users’ phone numbers. This incident has raised concerns among users of the popular app.

How did the incident happen?

Twilio revealed in a security alert that the unauthorised access was due to an unauthenticated endpoint in their system. This vulnerability allowed the ShinyHunters group to input phone numbers and verify whether they were linked to Authy accounts, exposing 33 million phone numbers.

The company has since secured the endpoint, preventing any further unauthenticated access. Twilio reassured users that there is no evidence that unauthorised actors accessed other sensitive data or the company’s systems beyond these phone numbers.

Twilio’s response and recommendations

Given this incident, Twilio strongly advises all Authy users to update their Android and iOS apps to the latest versions. These updates include enhanced security measures to protect against potential threats. Twilio also warns that the stolen phone numbers could be used for phishing (fraudulent emails) and smishing (fraudulent text messages) attacks. Therefore, users should remain vigilant and cautious about any suspicious communications.

This is not the first time Twilio has faced a security incident. Two years ago, unauthorised actors successfully phished several employees to access data from over 100 Twilio customers. This previous incident highlights the ongoing challenge of securing digital platforms against increasingly sophisticated cyber threats.

Protecting yourself from future attacks

Twilio’s latest security incident underscores the importance of staying updated with the newest app versions and being aware of potential phishing and smishing attempts. Users should regularly check for updates and apply them promptly to protect their accounts. Additionally, being cautious about unsolicited messages and verifying the authenticity of communications can help prevent falling victim to these attacks.

Twilio continues improving its security measures to protect its users and prevent future incidents. Taking proactive steps and staying informed can better safeguard your personal information against cyber threats.

Editor’s note: This story has been updated with a response from Twilio. Twilio has seen no evidence that the threat actors breached its systems or obtained access to its systems or other sensitive internal data. As a precaution, Twilio is requesting all Authy users to update to the latest Android and iOS apps for the latest security updates and encourages all Authy users to stay diligent and maintain heightened awareness around phishing and smishing attacks.

Hot this week

Meta accelerates AI innovation in Singapore with Llama Incubator Program Demo Day

Meta’s Llama Incubator Demo Day highlights its push to support open-source AI innovation and strengthen Singapore’s digital economy.

NVIDIA Spectrum-X Ethernet switches power next-generation AI data centres for Meta and Oracle

Meta and Oracle adopt NVIDIA Spectrum-X Ethernet switches to boost AI data centre performance and accelerate giga-scale model training.

Exabeam named a leader in 2025 Gartner Magic Quadrant for SIEM for sixth time

Exabeam has been named a Leader in the 2025 Gartner Magic Quadrant for SIEM for the sixth time, highlighting its AI-driven security innovation.

Global mobile app demand remains resilient as APAC leads growth surge

Adjust’s 2025 Mobile App Growth Report shows global app demand rising, led by APAC’s strong growth in gaming and entertainment.

Eaton launches 800 VDC power architecture to support next-generation AI data centres

Eaton unveils an 800 VDC power architecture to boost AI data centre efficiency, scalability, and support for high-density computing.

IPI Singapore: Enabling SMEs to scale through digital transformation and innovation partnerships

IPI Singapore shows how SMEs can scale through innovation, partnerships, and digital transformation to compete globally.

Semperis unveils cyberwar documentary spotlighting global defenders and reformed hackers

Semperis unveils Midnight in the War Room, a documentary revealing the human stories behind the global fight against cyber threats.

TeamViewer integrates AI-driven workplace solutions with Salesforce Agentforce IT Service

TeamViewer integrates AI-powered DEX and remote connectivity with Salesforce Agentforce IT Service to boost IT efficiency and reliability.

New study reveals rise of ‘AI natives’ shaping customer and workplace expectations in Asia Pacific

A Zoom study highlights the rise of ‘AI natives’ in Asia Pacific, revealing their growing impact on customer experience and workplace expectations.

Related Articles