/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Twilio says hackers accessed the accounts of 93 users of its 2FA app Authy as part of its recent breach, effectively letting the attackers generate login codes

U.S. messaging giant Twilio has confirmed hackers also compromised the accounts of some Authy users as part of a wider breach of Twilio's systems.

TechCrunch Carly Page

Context & Ripple Effects

Twilio had already attributed the wider incident to an SMS phishing attack on its staff, and Signal subsequently said the same breach exposed phone numbers and SMS verification codes for about 1,900 users. The Authy disclosure extends the impact from account information to the authentication codes themselves.

Later reporting that attackers identified Authy users' phone numbers shows that Authy remained a distinct exposure point in Twilio's security record, not merely a peripheral feature of the original incident.

First-order effects

  • The 93 compromised Authy users face immediate account-security risk because attackers could generate the two-factor codes tied to their registered devices.
  • Twilio must treat the breach as an authentication-service incident, rather than solely unauthorized access to customer-account information.

Second-order effects

  • Services relying on Twilio during the breach, including Signal, have to assess downstream exposure separately because the incident affected more than one verification channel.
  • Authy's security posture becomes more consequential for customers deciding whether a communications provider can also serve as a factor in their login defenses.

Third-order effects

  • The incident illustrates how phishing of a provider's staff can concentrate risk across its customer communications and authentication products, increasing the value of separating those dependencies.
  • If repeat Authy-related exposure persists, authentication vendors will face greater pressure to limit what account or phone data can enable access to verification workflows.

The trend: Security failures at communications providers are increasingly being evaluated by their downstream effect on the authentication systems and services built on top of them.

Discussion

  • @campuscodi Catalin Cimpanu on x
    Identity and authentication provider Okta said in a disclosure today that it is one of the companies impacted by the recent Twilio hack Okta says a threat actor named Scatter Swine used its Twilio account to collect OTP codes sent to some phone numbers https://sec.okta.com/... ht…
  • @zackwhittaker Zack Whittaker on x
    New: Twilio's breach just keeps getting worse, now confirming that hackers also compromised the accounts of nearly 100 users of its Authy two-factor authentication app, reports @carlypage_. https://techcrunch.com/...
  • @teriradichel @teriradichel on x
    Phishers who hit Twilio and Cloudflare stole 10k credentials from 136 others [TR: If you get a text message telling you to urgently log into a site, go to a browser and login directly rather than clicking the link in tho text message.] https://arstechnica.com/...
  • @henryistakentoo @henryistakentoo on x
    Hey - almost like a centralized, cloud-based TOTP solution may not be a great move. Local TOTP, (securely!) synced TOTP, or ideally U2F people. https://twitter.com/...
  • @josephmenn Joseph Menn on x
    #Twilio getting breached is bad, since it means text second factors in two-factor authentication can be intercepted. Twilio's #Authy getting breached as well is worse, since its app is a stronger second factor and also can add new devices. https://techcrunch.com/...
  • @adam_k_levin Adam Levin on x
    Data breaches seem to be picking up steam of late: https://techcrunch.com/...
  • @jbursz Jessica Bursztynsky on x
    DoorDash says it was hit by a data breach that exposed customers' information like name, address & partial payment card info. “The advanced tactics used appear to be connected to a wider phishing campaign that has targeted a number of other companies.” https://doordash.news/...
  • @campuscodi Catalin Cimpanu on x
    Twilio... the hack that keeps on giving https://twitter.com/...