Cointime

Download App
iOS & Android

Authy 2FA app leaks phone numbers that could be used for SMS phishing

  • Wechat scan to share

According to a security alert post released by application developer Twilio on July 1st, hackers gained access to the Authy Android application database, allowing them to identify data associated with accounts, including phone numbers. The post notes that the accounts themselves were not compromised, meaning that attackers were unable to obtain authentication credentials. However, leaked phone numbers may be used for phishing and SMS phishing attacks in the future. Therefore, Twilio encourages Authy users to remain vigilant and be highly alert to any received messages. Users of centralized trading platforms typically rely on Authy for two-factor authentication (2FA). It generates a code on the user's device, which the trading platform may require before executing sensitive tasks such as withdrawals or transfers. Authy is sometimes compared to Google's Authenticator app, which has similar functionality.

Comments

All Comments

Recommended for you