Fun

Authy 2FA app leaked phone numbers that may be used for text phishing

News Feed - 2024-07-04 05:07:00

Christopher Roark3 hours agoAuthy 2FA app leaked phone numbers that may be used for text phishingTwilio, the developer of the Authy authenticator app, said user phone numbers were leaked to attackers but accounts themselves were not compromised.796 Total views11 Total sharesListen to article 0:00NewsOwn this piece of crypto historyCollect this article as NFTJoin us on social networksHackers gained access to the Authy Android app database and “were able to identify data associated with [accounts], including phone numbers,” according to a July 1 security alert post issued by the app’s developer, Twilio.


The accounts themselves “are not compromised,” the post stated, implying that the attackers were not able to gain authentication credentials. However, the exposed phone numbers may be used for “phishing and smishing attacks” in the future. Because of this risk, Twilio encouraged Authy users to “stay diligent and have heightened awareness around the texts they are receiving.”Twilio security alert regarding Authy data breach. Source: Twilio


Related:What is a phishing attack in crypto, and how to prevent it?


Centralized exchange users often rely on Authy for two-factor authentication (2FA). It generates a code on the user’s device, which the exchange may ask for before it performs withdrawals, transfers or other sensitive tasks. Exchanges Gemini and Crypto.com both use Authy as their default 2FA app, and Coinbase, Binance and many other exchanges allow it as an option.


Authy is sometimes compared to Google’s Authenticator app, which has a similar purpose and is a competitor.


The attacker gained access through an “unauthenticated endpoint,” according to the post. The team has secured this endpoint, and the app no longer accepts unauthenticated requests going forward. It encouraged users to upgrade to the latest version of the app, which contains security improvements.


Twilio claimed that users’ authenticator codes have not been compromised, so the attackers should not be able to access their exchange accounts. “We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data,” the company stated.


According to a report from Seeking Alpha, the hack was performed by the ShinyHunters cybercriminal group, which “leaked a text file that purportedly shows the 33M phone numbers registered with Authy.” In 2021, cybersecurity blog Restoreprivacy reported that this same criminal group was responsible for an AT&T data breach that resulted in the data of 51 million customers being released online.


Authenticator apps were developed to prevent SIM swap attacks, a type of social engineering scheme that involves convincing a phone company to transfer a user’s phone number to the attacker. Once the attacker gains control of the user’s phone account, they use it to receive the user’s 2FA codes without needing to physically possess the user’s phone.


This type of attack is still prevalent today, as some users still receive 2FA codes through text messaging instead of through an app. On June 12, blockchain security firm SlowMist reported that millions of dollars were recently lost by OKX users due to SIM swap attacks.


Magazine: Crypto-Sec: Phishing scammer targets Hedera users, address poisoner gets $70K# Blockchain# Business# Hackers# Authentication# Cryptocurrency Exchange# Cybersecurity# HacksAdd reaction

News Feed

Joe Biden drops out of United States presidential race
Ciaran Lyons5 hours agoJoe Biden drops out of United States presidential raceUnited States President Joe Biden has announced he will bow out of the 2024 presidential election.8550 Total views8 Total sharesListen to artic
Helen Partz11 hours agoSecuritize acquires $40B crypto fund manager OnrampDigital securities firm Securitize will provide new alternative assets to major cryptocurrency fund managers like WisdomTree and Valkyrie Invest.3
BlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator to connect startups and VCs at Startup Connect
Helen Partz13 hours agoBlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator to connect startups and VCs at Startup ConnectBlockShow X BlockDown Asia 2024 and Cointelegraph Accelerator are set to host Startup Con
Biggest Movers: AVAX Hits Multi-Month Peak, as MATIC Jumps to 1-Week High
Biggest Movers: AVAX Hits Multi-Month Peak, as MATIC Jumps to 1-Week High Avalanche moved to a multi-month high on Jan. 24, after reports that the number of bitcoin on its network
David Attlee57 minutes agoIRS extends comments period for new crypto tax rule to mid-NovemberThe proposed rules are supposed to come into effect in 2026, impacting sales and exchanges conducted in 2025.334 Total views3 T
Can Bitcoin whales protect BTC price from new $48K downside target?
William Suberg14 hours agoCan Bitcoin whales protect BTC price from new $48K downside target?Bitcoin is not filling traders with hope as a stubborn BTC price range endures despite mass whale purchasing.6203 Total views18
Derek Andersen5 hours agoLayerZero’s market shifting, there’s a better environment ahead for everyone, CEO saysLayerZero CEO Bryan Pellegrino is optimistic about the future of the blockchain industry and the “reall
WIF Bulls Charge Toward $2.89 As Key Resistance Test Looms
Este artículo también está disponible en español. Recent trading activity reveals that WIF is gaining bullish momentum, with its price surging toward the critical $2.89 r
William Suberg17 hours agoBTC price due for $31K as analyst says ‘disinflation’ boosting BitcoinBitcoin and crypto markets seem ready to put in a “major move,” commentary concludes, as BTC price action coils up b
Tom Mitchelhill7 hours agoPolychain Capital, Coinfund raise $350M for new crypto funds: ReportPolychain Capital raised $200M for its newest fund while Coinfund raised a better-than-expected $152 million.1624 Total views1
DePINs are a proven path to crypto mass adoption — XYO co-founder
Jonathan DeYoung12 hours agoDePINs are a proven path to crypto mass adoption — XYO co-founderXYO co-founder Markus Levin argues that DePINs can make AI more trustworthy, empower users and businesses alike, and usher in
BSN and TON Labs to Provide Chinese Developer Community With Unique TON Technology
BSN and TON Labs to Provide Chinese Developer Community With Unique TON Technology sponsored Thanks to TON Labs, BSN will now be able to produce real-life applica