Twilio says “threat actors” identified its 2FA app Authy users' phone numbers; last week, ShinyHunters claimed to have stolen 33M phone numbers from Twilio
Last week, a hacker claimed to have stolen 33 million phone numbers from U.S. messaging giant Twilio.
Context & Ripple Effects
Twilio’s disclosure follows ShinyHunters’ claim that it obtained 33 million phone numbers, while leaving the relationship between the claim and the identified Authy-user numbers unresolved in the supplied record.
This is not Authy’s first security-relevant incident: a 2022 breach compromised 93 Authy accounts and registered devices, and the same broader Twilio incident exposed Signal users’ phone numbers and SMS verification codes. That history makes phone-number exposure consequential even when it is not itself account access.
First-order effects
- Authy users whose numbers were identified face more targeted phishing, impersonation, and account-recovery attempts tied to a known 2FA service.
- Twilio must contain the exposure and communicate the distinction between phone-number identification and any compromise of Authy accounts or authentication codes.
Second-order effects
- Because phone numbers are commonly used as identity and recovery signals, affected users and services may need to scrutinize SMS-based verification and recovery flows for targeted abuse.
- The disclosure renews pressure on authentication providers to reduce reliance on phone-number-based identity signals, especially after Twilio’s earlier staff SMS-phishing intrusion.
Third-order effects
- If repeated exposures keep making phone-number datasets useful for attackers, multi-factor authentication will increasingly be judged on resistance to recovery and social-engineering attacks, not just on code generation.
- The pattern points toward greater separation between a user’s phone number and their authentication identity, though this disclosure alone does not establish that a broader industry shift is underway.
The trend: Phone numbers are becoming a high-value attack-enablement dataset, pushing authentication systems to harden the identity and recovery layers around 2FA.