Twilio says hackers accessed the accounts of 93 users of its 2FA app Authy as part of its recent breach, effectively letting the attackers generate login codes
U.S. messaging giant Twilio has confirmed hackers also compromised the accounts of some Authy users as part of a wider breach of Twilio's systems.
Context & Ripple Effects
Twilio had already attributed the wider incident to an SMS phishing attack on its staff, and Signal subsequently said the same breach exposed phone numbers and SMS verification codes for about 1,900 users. The Authy disclosure extends the impact from account information to the authentication codes themselves.
Later reporting that attackers identified Authy users' phone numbers shows that Authy remained a distinct exposure point in Twilio's security record, not merely a peripheral feature of the original incident.
First-order effects
- The 93 compromised Authy users face immediate account-security risk because attackers could generate the two-factor codes tied to their registered devices.
- Twilio must treat the breach as an authentication-service incident, rather than solely unauthorized access to customer-account information.
Second-order effects
- Services relying on Twilio during the breach, including Signal, have to assess downstream exposure separately because the incident affected more than one verification channel.
- Authy's security posture becomes more consequential for customers deciding whether a communications provider can also serve as a factor in their login defenses.
Third-order effects
- The incident illustrates how phishing of a provider's staff can concentrate risk across its customer communications and authentication products, increasing the value of separating those dependencies.
- If repeat Authy-related exposure persists, authentication vendors will face greater pressure to limit what account or phone data can enable access to verification workflows.
The trend: Security failures at communications providers are increasingly being evaluated by their downstream effect on the authentication systems and services built on top of them.