Twilio
Disclosed Jul 1, 20242 years agoUnverified
Unauthenticated Authy endpoint let attackers enumerate 33 million phone numbers
Twilio confirmed that threat actors used an unauthenticated endpoint to identify data tied to Authy two-factor app accounts, including phone numbers, after the ShinyHunters group claimed 33 million numbers. Twilio secured the endpoint and told users to update the app.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 1, 2024 |
| Attack | Scraping |
| Data exposed | Phone numbers |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Twilio says hackers identified cell phone numbers of two-factor app Authy userstechcrunch.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jul 1, 2024 |
Other breaches at Twilio
| Breach | Affected | ||||
|---|---|---|---|---|---|
| SMS phishing of employees gives 0ktapus hackers access to Twilio customer dataAug 7, 20224 years agoPhishing | Aug 7, 20224 years ago | Phishing | Telecom | Confirmed | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.