/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Twilio says “threat actors” identified its 2FA app Authy users' phone numbers; last week, ShinyHunters claimed to have stolen 33M phone numbers from Twilio

Last week, a hacker claimed to have stolen 33 million phone numbers from U.S. messaging giant Twilio.

TechCrunch Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

Twilio’s disclosure follows ShinyHunters’ claim that it obtained 33 million phone numbers, while leaving the relationship between the claim and the identified Authy-user numbers unresolved in the supplied record.

This is not Authy’s first security-relevant incident: a 2022 breach compromised 93 Authy accounts and registered devices, and the same broader Twilio incident exposed Signal users’ phone numbers and SMS verification codes. That history makes phone-number exposure consequential even when it is not itself account access.

First-order effects

  • Authy users whose numbers were identified face more targeted phishing, impersonation, and account-recovery attempts tied to a known 2FA service.
  • Twilio must contain the exposure and communicate the distinction between phone-number identification and any compromise of Authy accounts or authentication codes.

Second-order effects

  • Because phone numbers are commonly used as identity and recovery signals, affected users and services may need to scrutinize SMS-based verification and recovery flows for targeted abuse.
  • The disclosure renews pressure on authentication providers to reduce reliance on phone-number-based identity signals, especially after Twilio’s earlier staff SMS-phishing intrusion.

Third-order effects

  • If repeated exposures keep making phone-number datasets useful for attackers, multi-factor authentication will increasingly be judged on resistance to recovery and social-engineering attacks, not just on code generation.
  • The pattern points toward greater separation between a user’s phone number and their authentication identity, though this disclosure alone does not establish that a broader industry shift is underway.

The trend: Phone numbers are becoming a high-value attack-enablement dataset, pushing authentication systems to harden the identity and recovery layers around 2FA.

Discussion

  • @rstephens Robert Stephens on threads
    Switch to passkeys wherever you can
  • @matthew_d_green Matthew Green on x
    The first rule of data breaches: if it exists in a database on the Internet, it will be stolen. The second rule of data breaches: the service that lost your data will be incredibly vague about exactly what the hackers took, because it's way worse than you imagine.
  • @bleepincomputer @bleepincomputer on x
    Twilio says that the API endpoint has now been secured and has released new versions of the Authy app.
  • @bleepincomputer @bleepincomputer on x
    An unauthenticated Authy API endpoint allowed threat actors to feed a massive list of phone numbers to the endpoint and verify if they are registered with the MFA platform. The threat actors claimed to verify over 33 million phone numbers (unconfirmed) used with Authy.
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Hackers say they stole 33 million cell phone numbers of users of two-factor app Authy. Twilio (owner of Authy) confirmed “threat actors were able to identify” phone numbers, but didn't say how many. The risk is better tailored phishing attacks. https://techcrunch.com/...
  • r/technews r on reddit
    Twilio says hackers identified cell phone numbers of two-factor app Authy users
  • r/Bitwarden r on reddit
    Hackers exploit Authy API, accessing possibly 30 millions of phone numbers (and device_lock, device_count).  Twilio takes action to secure endpoint. …
  • r/cybersecurity r on reddit
    Twilio says hackers identified cell phone numbers of two-factor app Authy users |  TechCrunch