A recent data breach by the ShinyHunters group has resulted in the leak of 33 million phone numbers from Authy accounts. The breach was caused by an unauthenticated API endpoint that was accessed by attackers. Twilio, the parent company of Authy, has confirmed the breach and has taken steps to address the issue by updating its Android and iOS apps.
The leak of sensitive data from Authy accounts is a cause for concern for users of the two-factor authentication app. Attackers have likely plugged phone numbers into the unauthenticated API endpoint, which could lead to a wave of phishing attempts. It is important for Authy users to remain vigilant and update their app as soon as possible to ensure their account status and device count are secure.
Key Takeaways
- ShinyHunters group caused a data breach that led to the leak of 33 million phone numbers from Authy accounts
- Attackers appear to have accessed an unauthenticated API endpoint to obtain the sensitive data
- Authy users should update their app immediately to ensure their account status and device count are secure
Data Breach by ShinyHunters Group Will Likely Spark Phishing Wave
The recent data breach by the ShinyHunters group has exposed customer phone numbers associated with Authy, along with “other data.” While there is no evidence that sensitive data or Twilio's internal systems were accessed, the breach is particularly concerning because Authy is a popular two-factor authentication app that provides login verification codes to mobile devices. ShinyHunters posted a dump of 33 million phone numbers to BreachForums that were purportedly from Authy. The breach has prompted Twilio to urge all Authy users to update their Android and iOS apps to receive security updates.
The most likely outcome of the data breach will be a wave of phishing attempts on Authy users. Attackers may attempt to craft authentic-looking messages that appear to come from Authy or Twilio themselves. Users should be especially wary of any text messages that seem authentic but that come out of the blue and ask for a password/code to be entered or that attempt to link to an external site.
Jason Kent, Hacker in Residence at Cequence, explains that the breach is an example of the standard script for breaches in the API era. An API endpoint that accepts data and gives responses on that data needs to be covered with both authentication and authorization, or someone will abuse the endpoint. In this case, the attackers likely targeted the phone numbers associated with Authy accounts. If they want to take over someone's account that is using Authy's MFA, they need to know what number the user used to sign that account up with and perform a SIM swap to get the MFA code sent to the new phone. This is a reverse attack where the MFA service provider was able to validate the numbers first, and now the SIM swapping attacks can commence.
Twilio has since put authentication on the endpoint in question, but it is still unknown if anyone has bought the 33 million records lost in the data dump. Authy users are advised to understand that their MFA service may be compromised and any service using Authy as its MFA should take additional actions to ensure a SIM swap wasn't recent on the account and ensure the end-user has additional authentication parameters in place to validate if the user is intentionally attempting something they shouldn't.
Attackers Appear to Have Plugged Phone Numbers into Unauthenticated API Endpoint
According to the available information, the data breach that exposed 33 million Authy phone numbers appears to have been caused by attackers plugging a massive “phone book” of numbers into an unauthenticated API endpoint to see which ones were associated with an account. The group behind the breach, ShinyHunters, likely used a list of phone numbers that had been obtained from prior data breaches.
The vulnerable API endpoint appears to have only returned account ID numbers and values for account status, device count, and whether a device was locked when presented with a valid phone number associated with an Authy account. The breach does not appear to have involved access to internal systems, but Authy account holders should be cautious of incoming texts and ensure that old accounts with recycled passwords are not still active.
It is possible that the phone numbers obtained during this breach could now be paired with other leaked information, so affected individuals should remain vigilant. The onus of protecting this data falls on the company hosting it, and data privacy regulations in most countries require companies to take adequate measures to safeguard user data.
However, scraping and abusing API endpoints is not necessarily strictly illegal and is done by AI and marketing companies among others. At present, US federal law does not adequately address this issue and only a handful of states have developed their own relevant laws. In the EU, fines and penalties for data breaches are more common, but the situation is different in the US.
Twilio has experienced two data breaches in 2022, both attributed to the “0ktapus” group. In both cases, the attackers obtained credentials by pretending to be from the IT department during social engineering phone calls to customer support. These attacks involved downstream access to some of Twilio's customers and subsidiaries, including Authy, which saw 93 accounts compromised to the point that attackers could add unauthorized devices to them.
It is worth noting that Twilio has recently disclosed another data breach to its customers that involves a third-party vendor for a backup carrier. The vendor, IdentifyMobile, may have exposed SMS text information to the open internet by improperly configuring an AWS S3 bucket that was left open from the start of 2024 to May 15. However, this data breach appears to be limited to impacting customers in France, Italy, Burkina Faso, Ivory Coast, and Gambia.
In conclusion, the API endpoint issue that led to the exposure of 33 million Authy phone numbers highlights the importance of companies taking adequate measures to safeguard user data. While scraping and abusing API endpoints is not necessarily strictly illegal, it is important for companies to be aware of the risks and take steps to mitigate them. The onus of protecting user data falls on the company hosting it, and data privacy regulations require companies to take adequate measures to safeguard user data.
Frequently Asked Questions
What should Authy users do following the reported data breach?
Authy users should immediately update their iOS or Android app to the latest version. They should also change their Authy account password and enable multi-device functionality to avoid future data breaches. Additionally, they should monitor their account activity for any suspicious behavior and report it to Authy customer support.
How can consumers protect themselves from potential harm after their phone numbers are exposed?
Consumers can protect themselves by being vigilant about any suspicious phone calls or texts. They should not provide personal information to unknown callers or click on any suspicious links. They should also monitor their financial accounts for any unauthorized transactions and report them immediately.
What are the implications of a data breach for two-factor authentication apps?
A data breach for two-factor authentication apps can compromise the security of user accounts and lead to potential financial loss or identity theft. It can also damage the reputation of the app and the company behind it.
How can users secure their accounts if their authentication data is compromised?
Users can secure their accounts by changing their passwords and enabling multi-factor authentication. They should also monitor their account activity for any suspicious behavior and report it to the app's customer support.
What are the typical consequences of an unsecured API endpoint leading to a data breach?
The typical consequences of an unsecured API endpoint leading to a data breach include compromised user data, financial loss, and damage to the company's reputation. It can also result in legal action and fines.
How do companies typically respond to a data breach involving customer information?
Companies typically respond to a data breach involving customer information by notifying affected customers, investigating the cause of the breach, and implementing measures to prevent future breaches. They may also offer credit monitoring or identity theft protection services to affected customers.
