The Authy app, one of the most popular for two-factor authentication on your smartphone, has been hacked, and your phone number might have been leaked.
Authy, recognized worldwide as one of the most used two-factor authentication (2FA) applications, has suffered a hack that has compromised a significant amount of data. Twilio, Authy’s parent company, recently reported a security breach that allowed access to users’ personal information.
What kind of information? According to the company, the attackers accessed the personal data of 33 million users, including the phone numbers of associated accounts.
Who’s responsible? Authy has taken responsibility, indicating that they left a “backdoor” in an “unauthenticated endpoint” that allowed access to this information. Although it is a breach, there is no evidence that the data was stolen by a hacker.
Is it resolved? Yes, Authy and Twilio have confirmed that the endpoint is no longer accessible without authentication, eliminating the vulnerability. However, the company has issued several recommendations for those affected.
Does the Authy hack affect you as a user?
The company has not confirmed what percentage of its customers were affected. It is unclear if the 33 million compromised data points represent all iOS and Android users or just a portion. It’s a significant number, so if you use Authy, your phone number might be exposed.
Is it problematic? While any personal data breach is concerning, this case is not alarming. Authy does not have access to your login information, so your passwords associated with two-factor authentication should not be compromised.
Currently, according to 9to5mac, potential attackers can know three things about you: that you use a two-factor authentication service, that it is Authy, and your phone number.
Beware of calls and SMS Although the leaked information is not enough to access your accounts or perform a personal attack, it could be used for phishing and smishing scams through emails or SMS messages.
While Authy accounts are not compromised, attackers might attempt to use the phone number associated with Authy accounts to carry out phishing and smishing attacks. All Authy users are encouraged to be diligent and more cautious about the text messages they receive.
Twilio Blog In summary, if you are an Authy user, the recommendation is to update to the latest versions on iOS and Android and be cautious with the communications you receive. Messages can be very convincing due to the leaked data, so be particularly wary of messages like the following:
“After the hack to our Authy app, your information might be at risk. Click on the following link and confirm your details to continue using the application.”
Attackers might have your number, know that you use Authy, and be aware of the recent hack, so be very careful with the links you open from your devices.
“Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken measures to protect this endpoint and no longer allow unauthenticated requests.
We have not seen any evidence that the threat actors have breached Twilio’s systems or gained access to sensitive internal data. As a precaution, we are asking all Authy users to update to the latest versions of Android and iOS to get the latest security updates, and we encourage all Authy users to be more vigilant and aware of phishing and smishing attacks.”
By: Nestor Castillo, ForAllTechNews Director
