Signal says attackers accessed the phone numbers and SMS verification codes for around 1,900 users as part of the recent Twilio breach
just reasons I don't understand. Can somebody explain those reasons to me? https://twitter.com/... Joseph Menn / @josephmenn : Every time there is a high-end attack on a critical end-to-end encrypted app that fails to obtain content, I am reminded how many even Western officials want to stop end-to-end encryption, which is close to the only thing in tech security that actually works. https://twitter.com/... Jenn / @jennschiffer : between digital ocean emailing yesterday about impact from a mailchimp hack, the heroku disaster, and now this - it's truly the year of learning the ingredients in the platforms we consume 😅🤘 https://twitter.com/... @freedomofpress : A recent breach of Twilio could have allowed attackers to take over users' accounts by registering their Signal number on a new device. This is why we recommend journalists enable “Registration Lock” on Signal. Here's how: https://freedom.press/... https://twitter.com/... Dino A. Dai Zovi / @dinodaizovi : It's a testament to Signal's design that a Twilio breach only allows an attacker to assume a target account's phone number (which also notifies all conversations of their new safety number) and doesn't compromise *any* data. Good proactive security designs prepare for breaches. https://twitter.com/... @signalapp : We have identified and are contacting the 1,900 potentially affected users. We are prompting them to re-register their Signal numbers and encouraging them to enable registration lock. We are also working with Twilio to ensure they upgrade their security practices. 3/ @nohackme : i ❤️ that @signalapp considered this very attack in their threat modeling, and developed a mitigation. settings>account>registration lock https://twitter.com/... Alex Radocea / @defendtheworld : I feel like signal continues to underplay how terrible of an idea phone-number based identity is despite being convenient for adoption. Twilio's customer support isn't the weakest point for SMS... it's the global telephony system itself. https://support.signal.org/... @combat_boot : Oopsie. Especially as certain organisation was touting app as most secure thing ever. Nothing is 100% & leading ppl to believe that it is, encourages risky behaviour. Trivial number of users involved but some targeted. Should serve as warning ref trust https://www.bleepingcomputer.com/ ... https://twitter.com/... J. A. Guerrero-Saade / @juanandres_gs : Honestly, let's take a minute to appreciate that @signalapp was built to guard precisely against this sort of attack. Reward and applaud well thought out security engineering in action! (h/t @dinodaizovi for the perspective) https://twitter.com/... Amanda Silberling / @asilbwrites : If you're a journalist using Signal to talk to sources, go to settings —> account and change your pin + turn on registration lock https://twitter.com/... Carly Page / @carlypage_ : so it looks like one of those 125 customers was... Signal 😳 https://techcrunch.com/... @briankrebs : Learned something new about Signal from their rundown of how some users were affected by the Twilio phishing incident: “Registration lock,” which requires your Signal PIN to register your phone number again with Signal https://support.signal.org/... Kevin Collier / @kevincollier : Last week Twilio said 125 customers had been affected in its recent breach. Looks like “customers” meant individual orgs, and Signal was one of those. How many others do we know about? (And if you know of any that aren't public, please reach out) https://support.signal.org/...
Context & Ripple Effects
Twilio had already disclosed an SMS-phishing attack on its staff that exposed information tied to some customer accounts; Signal was among the 125 affected customers. The incident puts a communications provider’s account-verification layer between Signal and its users.
Signal’s encrypted content was not identified as exposed in the supplied coverage, but the phone-number and SMS-code path created a separate account-registration risk. Signal says it is working with Twilio on security-practice upgrades.
First-order effects
- Around 1,900 Signal users face the risk that attackers could register their phone numbers on new devices, potentially taking over those accounts.
- Signal must address an exposure originating in Twilio’s systems, while Twilio faces immediate pressure to strengthen the practices Signal says it is reviewing with the provider.
Second-order effects
- Twilio’s other customers must treat SMS-based verification as a shared-provider exposure rather than an isolated Signal issue; related coverage later identified compromised Authy accounts and registered devices.
- Signal’s dependence on SMS verification makes the account-recovery and registration boundary a focal point alongside its encrypted messaging protections.
Third-order effects
- The episode points to a security model in which end-to-end encryption can protect message content while identity and verification vendors remain a concentrated route to account compromise.
- If providers continue to serve both messaging and authentication customers, trust in those platforms will increasingly depend on securing employee-facing access and verification workflows, not only customer data stores.
The trend: Security scrutiny is shifting toward the identity and verification dependencies around encrypted services, where a provider breach can endanger accounts without exposing message content.