Skip to content

Twilio

Disclosed Jul 1, 20242 years agoUnverified

Unauthenticated Authy endpoint let attackers enumerate 33 million phone numbers

Twilio confirmed that threat actors used an unauthenticated endpoint to identify data tied to Authy two-factor app accounts, including phone numbers, after the ShinyHunters group claimed 33 million numbers. Twilio secured the endpoint and told users to update the app.

What is known

People affectedNot stated in the sources we have
DisclosedJul 1, 2024
AttackScraping
Data exposedPhone numbers
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalJul 1, 2024

Other breaches at Twilio

BreachAffected
SMS phishing of employees gives 0ktapus hackers access to Twilio customer dataAug 7, 20224 years agoPhishingUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about Twilio

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.