Twilio data breach gets a whole lot worse as it confirms hackers accessed Authy user phone numbers


The recent data breach affecting Twilio may have taken a rather unfortunate extra turn after new reports claim the hackers can single out Authy users from the archives.

The infamous ShinyHunters hacking collective recently said it stole 33 million phone numbers from Twilio, and the company has now revealed that the attackers were able to determine which of those phone numbers are used for its Authy service. For those unfamiliar with Authy, it is a popular multi-factor authentication (MFA) tool, which Twilio acquired back in 2015.

Read more…
Source: MSN News


Sign up for our Newsletter


Related:

  • CenterPoint Energy confirms hackers compromised networks and stole data, and the hackers claim theft of 7.5 million files

    September 16, 2026

    CenterPoint Energy has confirmed suffering a cyberattack and data theft, days after a criminal advertised the stolen files on an underground hacking forum. CenterPoint Energy is a large US energy utility company that delivers electricity and natural gas to homes and businesses. It employs roughly 8,800 people and operates around $48.3 billion in assets, as of ...

  • Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

    September 16, 2026

    The ShinyHunters hacking group has published hundreds of thousands of files from a Florida state database of vehicles and driver information. The hackers said they published the stolen data on its leak site “because the victim did not pay a ransom or cooperate and comply” with the hackers’ demands. The hackers said they breached the database, ...

  • Revolut confirms customer data breach through fake government requests

    September 12, 2026

    British fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including ...

  • Crypto customers targeted by scammers after email marketing provider breach

    September 11, 2026

    An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms. Brevo initially said an attacker had ...

  • ShinyHunters expose 6.4M in attack on medical supplier McKesson

    September 10, 2026

    McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP ...

  • More than 1 million users affected in Mathspace data breach across Australia and New Zealand

    September 7, 2026

    More than a million people, including students, school staff, and parents, have been affected following a data breach at Mathspace, according to the learning provider. The company said, in a blog post, “unauthorised parties had accessed an internal reporting system used by Mathspace” and the exposed information included names and email addresses. It said the attackers accessed ...