Fun

Authy 2FA app leaked phone numbers that may be used for text phishing

News Feed - 2024-07-04 05:07:00

Christopher Roark3 hours agoAuthy 2FA app leaked phone numbers that may be used for text phishingTwilio, the developer of the Authy authenticator app, said user phone numbers were leaked to attackers but accounts themselves were not compromised.796 Total views11 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksHackers gained access to the Authy Android app database and “were able to identify data associated with [accounts], including phone numbers,” according to a July 1 security alert post issued by the app’s developer, Twilio.


The accounts themselves “are not compromised,” the post stated, implying that the attackers were not able to gain authentication credentials. However, the exposed phone numbers may be used for “phishing and smishing attacks” in the future. Because of this risk, Twilio encouraged Authy users to “stay diligent and have heightened awareness around the texts they are receiving.”Twilio security alert regarding Authy data breach. Source: Twilio


Related:What is a phishing attack in crypto, and how to prevent it?


Centralized exchange users often rely on Authy for two-factor authentication (2FA). It generates a code on the user’s device, which the exchange may ask for before it performs withdrawals, transfers or other sensitive tasks. Exchanges Gemini and Crypto.com both use Authy as their default 2FA app, and Coinbase, Binance and many other exchanges allow it as an option.


Authy is sometimes compared to Google’s Authenticator app, which has a similar purpose and is a competitor.


The attacker gained access through an “unauthenticated endpoint,” according to the post. The team has secured this endpoint, and the app no longer accepts unauthenticated requests going forward. It encouraged users to upgrade to the latest version of the app, which contains security improvements.


Twilio claimed that users’ authenticator codes have not been compromised, so the attackers should not be able to access their exchange accounts. “We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data,” the company stated.


According to a report from Seeking Alpha, the hack was performed by the ShinyHunters cybercriminal group, which “leaked a text file that purportedly shows the 33M phone numbers registered with Authy.” In 2021, cybersecurity blog Restoreprivacy reported that this same criminal group was responsible for an AT&T data breach that resulted in the data of 51 million customers being released online.


Authenticator apps were developed to prevent SIM swap attacks, a type of social engineering scheme that involves convincing a phone company to transfer a user’s phone number to the attacker. Once the attacker gains control of the user’s phone account, they use it to receive the user’s 2FA codes without needing to physically possess the user’s phone.


This type of attack is still prevalent today, as some users still receive 2FA codes through text messaging instead of through an app. On June 12, blockchain security firm SlowMist reported that millions of dollars were recently lost by OKX users due to SIM swap attacks.


Magazine: Crypto-Sec: Phishing scammer targets Hedera users, address poisoner gets $70K# Blockchain# Business# Hackers# Authentication# Cryptocurrency Exchange# Cybersecurity# HacksAdd reaction

News Feed

Bitcoin.com Exchange Reveals Role in the Cryptopia Rescue Group
Bitcoin.com Exchange Reveals Role in the Cryptopia Rescue Group The world-class trading platform, Bitcoin.com Exchange announced it’s participating in the
Gwyneth, Shaq, Paris, Eminem — A Deep Dive Into the NFT Collecting Habits of the Rich and Famous
Gwyneth, Shaq, Paris, Eminem — A Deep Dive Into the NFT Collecting Habits of the Rich and Famous Over the last year, celebrities have been dabbling in non-fungible token (NFT) co
Attackers Drain Millions From Cover Protocol, Token Holders Attack Compensation Plan
Attackers Drain Millions From Cover Protocol, Token Holders Attack Compensation Plan Decentralized finance insurance project Cover protocol briefly suffered loss
Bitcoin Narrowly Avoids 7 Consecutive Red Daily Candles
Bitcoin (BTC) has rallied to gain nearly 5% in as many hours, narrowly avoiding posting seven consecutive red daily candles for the sixth time ever. The last time that BTC posted se
Embr Releases Checkout to Future-Proof Trust in Web3 Payment Experiences
Embr Releases Checkout to Future-Proof Trust in Web3 Payment Experiences sponsored Embr is an all-remote corporation building a global Web3 fundraising infrastructure, and Checkout
Anton Churyumov9 hours agoDecentralized finance needs alternatives to blockchainCritics often overlook the inconvenient fact that “decentralized” blockchains in fact depend on centralized points of failure that have
Bitcoin Added to the Guinness Book of World Records as the ‘First Decentralized Cryptocurrency’
Bitcoin Added to the Guinness Book of World Records as the "First Decentralized Cryptocurrency" Since 1955 Guinness World Records (GWR) has published a reference book annually that
Solana NFT Marketplace Magic Eden Reveals Airdrop, Plans to Launch DAO
Solana NFT Marketplace Magic Eden Reveals Airdrop, Plans to Launch DAO On Tuesday, the Solana-based non-fungible token (NFT) marketplace Magic Eden announced the project is airdrop
Report: Freelance Workers in Argentina Among Most Active in LATAM Receiving Part of Paycheck in Crypto
Report: Freelance Workers in Argentina Among Most Active in LATAM Receiving Part of Paycheck in Crypto A recent report states that freelancing is experiencing a boom in Argentina,
Tom Mitchelhill4 hours agoCan PEPE make a comeback? Traders, analysts and Pepe maxis weigh inCointelegraph also spoke to developers purportedly behind a new PEPE token spin-off, who claim the new one is everything “the
Ether could outperform Bitcoin after spot ETF launch: Kaiko
Vince Quill2 hours agoEther could outperform Bitcoin after spot ETF launch: KaikoAccording to Bloomberg analyst Eric Balchunas, the highly-anticipated Ethereum ETFs could launch in the United States by July 23.1787 Total
Foundry Digital Launches Logistics Arm to Advance Standards in the Cryptocurrency Mining Industry
Foundry Digital Launches Logistics Arm to Advance Standards in the Cryptocurrency Mining Industry On Thursday, Foundry Digital LLC, the mining company and subsidiary of Digital Cur