* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Wednesday, December 24, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

    AMC Entertainment (NYSE:AMC) Sets New 52-Week Low – Here’s What Happened – MarketBeat

    AMC Entertainment (NYSE:AMC) Sets New 52-Week Low – Here’s What Happened – MarketBeat

    Concert venue, entertainment district planned for downtown Tampa – Spectrum Bay News 9

    Downtown Tampa to Unveil Thrilling New Concert Venue and Entertainment District

    $150 million, 12,500-seat entertainment venue coming to Houston in 2027 – CultureMap Houston

    Houston Set to Unveil a Spectacular $150 Million, 12,500-Seat Entertainment Venue in 2027

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    State officials warn of technology threatening online victims with sophisticated scams – Kauai Now

    State Officials Sound the Alarm on Sophisticated Tech-Driven Online Scams Targeting Victims

    Supply Chain Technology News of the Week – AI and Edge Systems Move from Insight to Action – Logistics Viewpoints –

    How AI and Edge Systems Are Revolutionizing Supply Chain Insights into Action

    Starbucks taps former Amazon veteran for technology leadership role – World Coffee Portal

    Starbucks Taps Former Amazon Executive to Drive Technology Innovation

    Technology Stocks Week Ahead: AI Spending Scrutiny, Fed Rate Path, and Holiday-Thin Trading to Drive Tech Stocks (Dec. 22–26, 2025) – ts2.tech

    Tech Stocks Outlook for Dec. 22-26, 2025: AI Investments, Fed Rate Moves, and Holiday-Thin Trading to Drive Market Action

    Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

    Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

    The 8 worst technology flops of 2025 – MIT Technology Review

    The 8 worst technology flops of 2025 – MIT Technology Review

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

    From The Pitt to Forever & Heated Rivalry , These Were The Best TV Shows Of 2025 – Refinery29

    AMC Entertainment (NYSE:AMC) Sets New 52-Week Low – Here’s What Happened – MarketBeat

    AMC Entertainment (NYSE:AMC) Sets New 52-Week Low – Here’s What Happened – MarketBeat

    Concert venue, entertainment district planned for downtown Tampa – Spectrum Bay News 9

    Downtown Tampa to Unveil Thrilling New Concert Venue and Entertainment District

    $150 million, 12,500-seat entertainment venue coming to Houston in 2027 – CultureMap Houston

    Houston Set to Unveil a Spectacular $150 Million, 12,500-Seat Entertainment Venue in 2027

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    State officials warn of technology threatening online victims with sophisticated scams – Kauai Now

    State Officials Sound the Alarm on Sophisticated Tech-Driven Online Scams Targeting Victims

    Supply Chain Technology News of the Week – AI and Edge Systems Move from Insight to Action – Logistics Viewpoints –

    How AI and Edge Systems Are Revolutionizing Supply Chain Insights into Action

    Starbucks taps former Amazon veteran for technology leadership role – World Coffee Portal

    Starbucks Taps Former Amazon Executive to Drive Technology Innovation

    Technology Stocks Week Ahead: AI Spending Scrutiny, Fed Rate Path, and Holiday-Thin Trading to Drive Tech Stocks (Dec. 22–26, 2025) – ts2.tech

    Tech Stocks Outlook for Dec. 22-26, 2025: AI Investments, Fed Rate Moves, and Holiday-Thin Trading to Drive Market Action

    Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

    Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

    The 8 worst technology flops of 2025 – MIT Technology Review

    The 8 worst technology flops of 2025 – MIT Technology Review

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Hackers abused API to verify millions of Authy MFA phone numbers

July 4, 2024
in Technology
Hackers abused API to verify millions of Authy MFA phone numbers
Share on FacebookShare on Twitter

Authy

Twilio has confirmed that an unsecured API endpoint allowed threat actors to verify the phone numbers of millions of Authy multi-factor authentication users, potentially making them vulnerable to SMS phishing and SIM swapping attacks.

Authy is a mobile app that generates multi-factor authentication codes at websites where you have MFA enabled. 

In late June, a threat actor named ShinyHunters leaked a CSV text file containing what they claim are 33 million phone numbers registered with the Authy service.

ShinyHunters sharing Twilio Authy data on a hacking forumShinyHunters sharing Twilio Authy data on a hacking forum
Source: BleepingComputer

The CSV file contains 33,420,546 rows, each containing an account ID, phone number, an “over_the_top” column, account status, and device count.

Twilio has now confirmed to BleepingComputer that the threat actors compiled the list of phone numbers using an unauthenticated API endpoint. 

“Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests,” Twilio told BleepingComputer.

“We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data. As a precaution, we are requesting all Authy users to update to the latest Android and iOS apps for the latest security updates and encourage all Authy users to stay diligent and have heightened awareness around phishing and smishing attacks.”

In 2022, Twilio disclosed it suffered breaches in June and August that allowed threat actors to breach its infrastructure and access Authy customer information.

Abusing unsecured APIs

BleepingComputer has learned that the data was compiled by feeding a massive list of phone numbers into the unsecured API endpoint. If the number was valid, the endpoint would return information about the associated accounts registered with Authy.

Now that the API has been secured, it can no longer be abused to verify whether a phone number is used with Authy.

This technique is similar to how threat actors abused an unsecured Twitter API and Facebook API to compile profiles of tens of millions of users that contain both public and non-public information.

While the Authy scrape only contained phone numbers, they can still be advantageous to users looking to conduct smishing and SIM swapping attacks to breach accounts.

ShinyHunters alludes to this in their post, stating, “You guys can join it on gemini or Nexo db,” suggesting that threat actors compare the list of phone numbers to those leaked in alleged Gemini and Nexo data breaches.

If matches are found, the threat actors could attempt to perform SIM swapping attacks or phishing attacks to breach the cryptocurrency exchange accounts and steal all the assets.

Twilio has now released a new security update and recommends that users upgrade to Authy Android (v25.1.0) and iOS App (v26.1.0), which includes security updates. It is unclear how this security update helps to protect users from threat actors using the scraped data in attacks.

Authy users should also ensure their mobile accounts are configured to block number transfers without providing a passcode or turning off security protections.

Furthermore, Authy users should be on the lookout for potential SMS phishing attacks that attempt to steal more sensitive data, such as passwords.

In what appears to be an unrelated breach, Twilio has also begun sending data breach notifications after a third-party vendor’s unsecured AWS S3 bucket exposed SMS-related data sent through the company.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/hackers-abused-api-to-verify-millions-of-authy-mfa-phone-numbers/

Tags: abusedhackerstechnology
Previous Post

Formula 1 governing body discloses data breach after email hacks

Next Post

OVHcloud blames record-breaking DDoS attack on MikroTik botnet

Google Cloud signs $10 billion deal with Palo Alto Networks – Network World

Google Cloud signs $10 billion deal with Palo Alto Networks – Network World

December 24, 2025
US economy grew much faster than expected in the third quarter, delayed report shows – Fox Business

US economy grew much faster than expected in the third quarter, delayed report shows – Fox Business

December 24, 2025
Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

December 24, 2025
Opinion | The MAHA Pipe Dream Is Going to Hurt MAGA the Most – The New York Times

How the MAHA Pipe Dream Could Jeopardize MAGA’s Future

December 24, 2025
In Pursuit of a Political Utopia – The New York Times

Pursuing the Dream of a Perfect Society: The Journey Toward a Political Utopia

December 23, 2025
EGLE approves hazardous waste facility’s license renewal over protests – Detroit Free Press

EGLE approves hazardous waste facility’s license renewal over protests – Detroit Free Press

December 23, 2025
Scientists Confirm the Incredible Existence of ‘Second Sound’ – Popular Mechanics

Scientists Unveil the Astonishing Reality of the ‘Second Sound’ Phenomenon

December 23, 2025
The Science That Will Shape 2026 – Gizmodo

The Science That Will Shape 2026 – Gizmodo

December 23, 2025
Supermodel shares secret battle with debilitating illness ‘destroying lungs’ – the-independent.com

Supermodel Opens Up About Her Secret Fight Against a Devastating Lung Disease

December 23, 2025
State officials warn of technology threatening online victims with sophisticated scams – Kauai Now

State Officials Sound the Alarm on Sophisticated Tech-Driven Online Scams Targeting Victims

December 23, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (984)
  • Economy (1,003)
  • Entertainment (21,880)
  • General (18,914)
  • Health (10,043)
  • Lifestyle (1,015)
  • News (22,149)
  • People (1,009)
  • Politics (1,017)
  • Science (16,218)
  • Sports (21,503)
  • Technology (15,985)
  • World (992)

Recent News

Google Cloud signs $10 billion deal with Palo Alto Networks – Network World

Google Cloud signs $10 billion deal with Palo Alto Networks – Network World

December 24, 2025
US economy grew much faster than expected in the third quarter, delayed report shows – Fox Business

US economy grew much faster than expected in the third quarter, delayed report shows – Fox Business

December 24, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version