Desk live·
ForensicPost
Breaches/Identity/File 24-0703

Twilio Confirmed 33 Million Authy Phone Numbers Through an Open Endpoint

An unauthenticated API let anyone check whether a phone number was registered to Authy, Twilio’s multi-factor authentication app. A list of 33 million confirmed numbers was published.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTwilio Authy
ActorUnattributed
S. Rosler9 min readConfidence: high2 sources reviewed

Twilio confirmed in July 2024 that an unsecured API endpoint had allowed attackers to verify the phone numbers of Authy users. A list of 33 million numbers, together with account identifiers and other non-personal fields, was published on a criminal forum. Twilio said the endpoint had been secured and that there was no evidence attackers obtained wider access.

The Value Is The Confirmation

A phone number on its own is not sensitive. A phone number confirmed to belong to someone who uses a multi-factor authentication app is a different object: it identifies a person who holds accounts worth protecting.

That is a targeting list for SIM-swap and for phishing that impersonates the very service the victim uses to stay safe. The same shape appears in the Trello scrape earlier in the year — an endpoint that turns a guess into a fact.

The Security Product Was The Exposure

Authy exists to protect accounts. Being an Authy user is therefore a signal, and the endpoint published that signal for 33 million people.

We have recorded second factors defeated in several ways — approved under pressure, relayed live, the check skipped server-side. This is a fifth: the factor held, and the fact of using it became the attack surface.

How we reported this

Compiled from Twilio’s confirmation and public reporting, listed below. The 33 million figure comes from the published dataset. Twilio reported no evidence of wider system access. Corrections: corrections@forensicpost.com.

Sources
  1. Twilio Confirms Data Breach After Hackers Leak 33M Authy User Phone NumbersSecurityWeek
  2. Hackers abused API to verify millions of Authy MFA phone numbersBleepingComputer
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary