Jonathan Care’s Post

View profile for Jonathan Care, graphic

Cybersecurity Expert | Gartner Veteran | GTM Advisor to Startups, Private Equity & Venture Funds | Board Advisor

Sigh... "Twilio has confirmed that an unsecured API endpoint allowed threat actors to verify the phone numbers of millions of Authy multi-factor authentication users, potentially making them vulnerable to SMS phishing and SIM swapping attacks. Authy is a mobile app that generates multi-factor authentication codes at websites where you have MFA enabled. In late June, a threat actor named ShinyHunters leaked a CSV text file containing what they claim are 33 million phone numbers registered with the Authy service."

Hackers abused API to verify millions of Authy MFA phone numbers

Hackers abused API to verify millions of Authy MFA phone numbers

bleepingcomputer.com

To view or add a comment, sign in

Explore topics