Twilio says accounts of 93 individual users of its 2FA app Authy and devices registered to their accounts were compromised as part of its recent breach
U.S. messaging giant Twilio has confirmed hackers also compromised the accounts of some Authy users as part of a wider breach of Twilio's systems.
Context & Ripple Effects
The Authy disclosure closes out an arc that began when Twilio disclosed an August 4 intrusion in which a 'sophisticated' actor used SMS-based phishing against its own staff to reach customer account data. The blast radius has widened since: Signal separately confirmed attackers pulled phone numbers and SMS verification codes for around 1,900 of its users from the same compromise.
What makes this latest confirmation notable is the target: Authy is Twilio's two-factor authentication product, so breaching it means attackers could potentially generate login codes for protected accounts — turning a security tool into an attack surface. The pattern also foreshadows what came later, when ShinyHunters claimed to have stolen 33M Authy user phone numbers in a separate 2024 incident.
First-order effects
- The 93 affected Authy users face immediate account-takeover risk, since compromised devices let attackers generate valid login codes for whatever services those users protected with Authy.
Second-order effects
- Companies relying on Twilio for authentication infrastructure — as Signal did — must now treat their own user bases as exposed through a vendor they don't control, pushing some toward bringing verification in-house or diversifying suppliers.
Third-order effects
- If SMS-based phishing keeps yielding upstream access to authentication providers, the industry's trust model shifts: 2FA vendors become high-value breach targets themselves, accelerating moves away from phone-number-based verification entirely.
The trend: Authentication providers are becoming prime breach targets, with each Twilio incident eroding confidence in centralized, phone-number-based two-factor systems.