Twilio confirmed in July 2024 that an unsecured API endpoint had allowed attackers to verify the phone numbers of Authy users. A list of 33 million numbers, together with account identifiers and other non-personal fields, was published on a criminal forum. Twilio said the endpoint had been secured and that there was no evidence attackers obtained wider access.
The Value Is The Confirmation
A phone number on its own is not sensitive. A phone number confirmed to belong to someone who uses a multi-factor authentication app is a different object: it identifies a person who holds accounts worth protecting.
That is a targeting list for SIM-swap and for phishing that impersonates the very service the victim uses to stay safe. The same shape appears in the Trello scrape earlier in the year — an endpoint that turns a guess into a fact.
The Security Product Was The Exposure
Authy exists to protect accounts. Being an Authy user is therefore a signal, and the endpoint published that signal for 33 million people.
We have recorded second factors defeated in several ways — approved under pressure, relayed live, the check skipped server-side. This is a fifth: the factor held, and the fact of using it became the attack surface.
Compiled from Twilio’s confirmation and public reporting, listed below. The 33 million figure comes from the published dataset. Twilio reported no evidence of wider system access. Corrections: corrections@forensicpost.com.