A Security Breach Affects Millions of Phone Numbers Linked to Twilio’s Authy Application
Twilio, a provider of cloud communications, has made public that unknown cybercriminals exploited an unauthenticated endpoint in Authy to access details related to Authy accounts, such as users’ phone numbers.
The organization has implemented measures to secure the endpoint so that it no longer accepts unauthenticated requests.
This development occurred shortly after an online alias named ShinyHunters released a database on BreachForums containing 33 million phone numbers reportedly obtained from Authy accounts.
Twilio-owned Authy, a widely used two-factor authentication (2FA) application, bolsters the security of user accounts by adding an extra layer of protection.

“Although we have no proof that the cybercriminals gained access to Twilio’s systems or other confidential information,” the company stated in a security alert dated July 1, 2024.
As a precautionary measure, it suggests that users update their Android (version 25.1.0 or higher) and iOS (version 26.1.0 or higher) applications to the most recent version.
Furthermore, it warns that the cybercriminals might try to exploit the phone numbers linked to Authy accounts for phishing and smishing attacks.
“We advise all Authy users to remain vigilant and be extra cautious about the messages they receive,” it added.
