Fun

Authy 2FA app leaked phone numbers that may be used for text phishing

News Feed - 2024-07-04 05:07:00

Christopher Roark3 hours agoAuthy 2FA app leaked phone numbers that may be used for text phishingTwilio, the developer of the Authy authenticator app, said user phone numbers were leaked to attackers but accounts themselves were not compromised.796 Total views11 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksHackers gained access to the Authy Android app database and “were able to identify data associated with [accounts], including phone numbers,” according to a July 1 security alert post issued by the app’s developer, Twilio.


The accounts themselves “are not compromised,” the post stated, implying that the attackers were not able to gain authentication credentials. However, the exposed phone numbers may be used for “phishing and smishing attacks” in the future. Because of this risk, Twilio encouraged Authy users to “stay diligent and have heightened awareness around the texts they are receiving.”Twilio security alert regarding Authy data breach. Source: Twilio


Related:What is a phishing attack in crypto, and how to prevent it?


Centralized exchange users often rely on Authy for two-factor authentication (2FA). It generates a code on the user’s device, which the exchange may ask for before it performs withdrawals, transfers or other sensitive tasks. Exchanges Gemini and Crypto.com both use Authy as their default 2FA app, and Coinbase, Binance and many other exchanges allow it as an option.


Authy is sometimes compared to Google’s Authenticator app, which has a similar purpose and is a competitor.


The attacker gained access through an “unauthenticated endpoint,” according to the post. The team has secured this endpoint, and the app no longer accepts unauthenticated requests going forward. It encouraged users to upgrade to the latest version of the app, which contains security improvements.


Twilio claimed that users’ authenticator codes have not been compromised, so the attackers should not be able to access their exchange accounts. “We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data,” the company stated.


According to a report from Seeking Alpha, the hack was performed by the ShinyHunters cybercriminal group, which “leaked a text file that purportedly shows the 33M phone numbers registered with Authy.” In 2021, cybersecurity blog Restoreprivacy reported that this same criminal group was responsible for an AT&T data breach that resulted in the data of 51 million customers being released online.


Authenticator apps were developed to prevent SIM swap attacks, a type of social engineering scheme that involves convincing a phone company to transfer a user’s phone number to the attacker. Once the attacker gains control of the user’s phone account, they use it to receive the user’s 2FA codes without needing to physically possess the user’s phone.


This type of attack is still prevalent today, as some users still receive 2FA codes through text messaging instead of through an app. On June 12, blockchain security firm SlowMist reported that millions of dollars were recently lost by OKX users due to SIM swap attacks.


Magazine: Crypto-Sec: Phishing scammer targets Hedera users, address poisoner gets $70K# Blockchain# Business# Hackers# Authentication# Cryptocurrency Exchange# Cybersecurity# HacksAdd reaction

News Feed

Refinable Authenticates Fine Jewelry Sale on Sotheby’s
Refinable Authenticates Fine Jewelry Sale on Sotheby’s press release PRESS RELEASE. HONG KONG – 10th October 2021– Refinable, a leading decentralized NFT marketplace
Bitcoin To $500,000: Standard Chartered Doubles Down On 2028 Target
Este artículo también está disponible en español. Standard Chartered’s global head of digital assets research, Geoffrey Kendrick, has reaffirmed his standout price fore
Fraud victims want China to recover $4.3B worth of Bitcoin seized by UK police
Ezra Reguerra46 minutes agoFraud victims want China to recover $4.3B worth of Bitcoin seized by UK policeUnited Kingdom authorities found 61,000 BTC when it raided a house rented by money launderers in 2021.294 Total vie
XRP Price Still On Track For $1.5T Market Cap And 27% Crypto Market Dominance
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
South African Regulator ‘Welcomes’ Binance’s Decision to Terminate Certain Services in the Country
South African Regulator "Welcomes" Binance"s Decision to Terminate Certain Services in the Country A South African regulator, the Financial Sector Conduct Authority (FSCA), says it
30% of Today’s Staked Ethereum Is Tied to Lido’s Liquid Staking, 8 ETH 2.0 Pools Command $8.1 Billion in Value
30% of Today"s Staked Ethereum Is Tied to Lido"s Liquid Staking, 8 ETH 2.0 Pools Command $8.1 Billion in Value In roughly three days Ethereum is expected to transition from a proof
Top 5 Cryptos to Invest in as Whales Accumulate Bitcoin After Trump Inauguration
After surging by over 60% in the last three months, thanks to Donald Trump’s victory, the selling pressure for Bitcoin is no longer a point of concern for the overall crypto market. In fact, large whales are now in
Donated or Inherited Virtual Assets to Be Taxed by South Korea’s NTS
Donated or Inherited Virtual Assets to Be Taxed by South Korea"s NTS Starting in the year 2022, donated or inherited virtual assets will be assessed and taxed accordingly, South Ko
A ‘Significant Increase’: UK Regulator Says 2.6 Million Residents Have Bought Cryptocurrencies
A "Significant Increase": UK Regulator Says 2.6 Million Residents Have Bought CryptocurrenciesThe UK’s top financial regulator has conducted a survey and found a “signif
Signature Bank Considered a Buy as Last Major Bank Standing in Crypto Market Amid Silvergate and SVB Troubles
Signature Bank Considered a Buy as Last Major Bank Standing in Crypto Market Amid Silvergate and SVB Troubles Amid the demise of Silvergate Bank and the troubles faced by Silicon V
Bitcoin will 'propel the next leg up' if key trading pattern confirms — Traders
Ciaran Lyons6 hours agoBitcoin will "propel the next leg up" if key trading pattern confirms — TradersThe inverse head and shoulders pattern forming "would make sense" if Bitcoin doesn"t "break straight
Palm-scanning identity protocol gets funding from over 20 VCs
Ezra Reguerra11 minutes agoPalm-scanning identity protocol gets funding from over 20 VCsHumanity Protocol claims it offers a less invasive alternative than iris scans, seemingly taking a jab at the popular digital identi