Fun

Authy 2FA app leaked phone numbers that may be used for text phishing

News Feed - 2024-07-04 05:07:00

Christopher Roark3 hours agoAuthy 2FA app leaked phone numbers that may be used for text phishingTwilio, the developer of the Authy authenticator app, said user phone numbers were leaked to attackers but accounts themselves were not compromised.796 Total views11 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksHackers gained access to the Authy Android app database and “were able to identify data associated with [accounts], including phone numbers,” according to a July 1 security alert post issued by the app’s developer, Twilio.


The accounts themselves “are not compromised,” the post stated, implying that the attackers were not able to gain authentication credentials. However, the exposed phone numbers may be used for “phishing and smishing attacks” in the future. Because of this risk, Twilio encouraged Authy users to “stay diligent and have heightened awareness around the texts they are receiving.”Twilio security alert regarding Authy data breach. Source: Twilio


Related:What is a phishing attack in crypto, and how to prevent it?


Centralized exchange users often rely on Authy for two-factor authentication (2FA). It generates a code on the user’s device, which the exchange may ask for before it performs withdrawals, transfers or other sensitive tasks. Exchanges Gemini and Crypto.com both use Authy as their default 2FA app, and Coinbase, Binance and many other exchanges allow it as an option.


Authy is sometimes compared to Google’s Authenticator app, which has a similar purpose and is a competitor.


The attacker gained access through an “unauthenticated endpoint,” according to the post. The team has secured this endpoint, and the app no longer accepts unauthenticated requests going forward. It encouraged users to upgrade to the latest version of the app, which contains security improvements.


Twilio claimed that users’ authenticator codes have not been compromised, so the attackers should not be able to access their exchange accounts. “We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data,” the company stated.


According to a report from Seeking Alpha, the hack was performed by the ShinyHunters cybercriminal group, which “leaked a text file that purportedly shows the 33M phone numbers registered with Authy.” In 2021, cybersecurity blog Restoreprivacy reported that this same criminal group was responsible for an AT&T data breach that resulted in the data of 51 million customers being released online.


Authenticator apps were developed to prevent SIM swap attacks, a type of social engineering scheme that involves convincing a phone company to transfer a user’s phone number to the attacker. Once the attacker gains control of the user’s phone account, they use it to receive the user’s 2FA codes without needing to physically possess the user’s phone.


This type of attack is still prevalent today, as some users still receive 2FA codes through text messaging instead of through an app. On June 12, blockchain security firm SlowMist reported that millions of dollars were recently lost by OKX users due to SIM swap attacks.


Magazine: Crypto-Sec: Phishing scammer targets Hedera users, address poisoner gets $70K# Blockchain# Business# Hackers# Authentication# Cryptocurrency Exchange# Cybersecurity# HacksAdd reaction

News Feed

Rwandan central bank proceeds with ambitious retail CBDC project
Derek Andersen2 hours agoRwandan central bank proceeds with ambitious retail CBDC projectThe African country is eyeing a tokenized retail CBDC with offline transfer capabilities as it heads toward a cashless economy.1050
Kazakhstan Shuts Down Over 100 Crypto Mining Farms
Kazakhstan Shuts Down Over 100 Crypto Mining Farms More than 100 crypto farms in Kazakhstan have terminated operations as a result of ongoing inspections of the mining sector. Auth
Paris Saint-Germain begins Web3 drive as a new blockchain validator for Chiliz Chain
Gareth Jenkinson14 hours agoParis Saint-Germain begins Web3 drive as a new blockchain validator for Chiliz ChainThe French football club aims to explore various avenues in the cryptocurrency sector, starting with becomi
Virgin Galactic’s Chamath Palihapitiya: Bitcoin Could Go to $1 Million, Everybody Should Own Some
Virgin Galactic"s Chamath Palihapitiya: Bitcoin Could Go to $1 Million, Everybody Should Own Some Virgin Galactic Chairman Chamath Palihapitiya has shared his bitcoin investment
Philippine Authorities Rescue Alleged Victims of ‘Crypto Trafficking Ring’
Philippine Authorities Rescue Alleged Victims of "Crypto Trafficking Ring" Philippine authorities say that they have rescued alleged victims of a “crypto trafficking ringR
Crypto Industry’s Favorite Messaging App Telegram Surpasses 500 Million Active Users
Crypto Industry"s Favorite Messaging App Telegram Surpasses 500 Million Active Users Telegram, a popular messaging app within the cryptocurrency space, surpassed
Ethereum’s firm $2,860 support signals path to $4,500 — Deribit
Josh O"Sullivan10 hours agoEthereum’s firm $2,860 support signals path to $4,500 — DeribitA Deribit report underscores Ethereum’s resilience at $2,860, pointing toward potential highs driven by recent ETF approvals
Laos Licenses 2 Cryptocurrency Trading Platforms
Laos Licenses 2 Cryptocurrency Trading Platforms The central bank of Laos has issued licenses to two cryptocurrency trading platforms. Lao Digital Assets Exchange (LDX) and Bitqik
First Republic Bank’s Shares Downgraded to Junk Status by S&P Global; Stock Slides More Than 25% Lower
First Republic Bank"s Shares Downgraded to Junk Status by S&P Global; Stock Slides More Than 25% Lower After UBS acquired Credit Suisse and close to a dozen financial institutions
David Attlee4 hours agoFrom Thailand to South Africa, regulators tighten their grip on crypto: Law Decoded, July 3–10South Africa’s financial regulator has announced that all crypto exchanges in the country must obta
Avalanche halts block production amid inscription wave launch
Ezra Reguerra11 hours agoAvalanche halts block production amid inscription wave launchAva Labs co-founder Kevin Sekniqi believes the issue may be related to a recently launched inscription wave.2337 Total views9 Total sh
Yearn Finance Vault Users Lock $139M: Farmers Claim Collateralized ETH Gathers 90% APY
Yearn Finance Vault Users Lock $139M: Farmers Claim Collateralized ETH Gathers 90% APYOn September 3, 2020, the well known Yearn Finance defi project “paused” the popula