Security

Twilio says breach also compromised Authy two-factor app users

Comment

Authy icon on an iPhone home screen
Image Credits: Bryce Durbin / TechCrunch

U.S. messaging giant Twilio has confirmed hackers also compromised the accounts of some Authy users as part of a wider breach of Twilio’s systems. Authy is Twilio’s two-factor authentication (2FA) app it acquired in 2015.

Twilio’s breach earlier this month, which saw malicious actors accessing the data of more than 100 Twilio customers after successfully phishing multiple employees, keeps growing in scale. Researchers this week linked the attack on Twilio and others to a wider phishing campaign by a hacking group dubbed “0ktapus,” which has stolen close to 10,000 employee credentials from at least 130 organizations since March.

Now, Twilio has confirmed that Authy users were also impacted by the breach.

In an update to its incident report on August 24, Twilio said that the hackers gained access to the accounts of 93 individual Authy users and registered additional devices, effectively allowing the attackers to generate login codes for any connected 2FA-enabled account.

The company said it has “since identified and removed unauthorized devices from these Authy accounts” and is advising affected Authy users, which it has contacted, to review linked accounts for suspicious activity. It’s also recommending that users review all devices tied to their Authy accounts and disable “allow Multi-device” in the Authy application to prevent new device additions.

While using any two-factor authentication is better than none, hackers are increasingly devising new ways to trick users into handing over app-based codes, which is generally far more difficult to obtain than codes sent by text message.

Twilio also said in the update that the number of compromised Twilio customers has increased from 125 to 163, with hackers accessing data at these organizations for a “limited period of time.” Twilio has not named its impacted customers, but some — like encrypted messaging app Signal — have notified their own users that they were affected by the Twilio breach.

Identity giant Okta on Thursday also confirmed it was compromised as a result of the Twilio breach. The company said in a blog post that the hackers — which it refers to as “Scatter Swine” — spoofed Okta login pages to target organizations that rely on the company’s single sign-on service. Okta said that when the hackers gained access to Twilio’s internal console, they obtained a “small number” of Okta customer phone numbers and SMS messages that contained one-time passwords. This marks the second time Okta has reported a security incident this year.

In its analysis of the phishing campaign, Okta said that Scatter Swine hackers likely harvested mobile phone numbers from data aggregation services that link phone numbers to employees at specific organizations. At least one of the hackers called targeted employees impersonating IT support, noting that the hacker’s accent “appears to be North American.” This may align with this week’s Group-IB investigation, which suggested one of the hackers involved in the campaign may reside in North Carolina.

DoorDash also confirmed this week that it was compromised by the same hacking group. The food delivery giant told TechCrunch that malicious hackers stole credentials from employees of a third-party vendor that were then used to gain access to some of DoorDash’s internal tools. The company declined to name the third-party, but confirmed the vendor was not Twilio.

DoorDash hit by data breach linked to Twilio hackers

More TechCrunch

The Rounds, the startup that delivers recurring grocery and household essentials in reusable packaging, announced on Monday its $24 million Series B funding round. The new capital will go toward…

The Rounds scoops up $24M to bring its ‘household restocking’ delivery service to more markets

The U.S. Department of Defense is a mammoth organization. It not only employs millions of service members and hundreds of thousands of civilian employees, but also has the world’s largest…

Defcon AI closes $44M seed round to solve a problem of ‘maximum complexity’: Military logistics

Eppo has closed a new funding round that values the company at over $100 million.

Eppo lands new cash to grow its app, website and AI experimentation business

Simulating the real world is a tremendously complex problem if you want to do it at any useful level of fidelity. Traditional techniques are holding back design teams at vehicle…

Beyond Math’s ‘digital wind tunnel’ puts a physics-based AI simulation to work on F1 cars

NASA and the space industry are in agreement: if we want to establish a permanent human presence on the moon, we’ll need to make use of every native resource we…

Starpath accelerates moon water mining plans with $12M in funding

AI models have proven capable of many things, but what tasks do we actually want them doing? Preferably drudgery — and there’s plenty of that in research and academia. Reliant…

Reliant’s paper-scouring AI takes on science’s data drudgery

Update: Authorities have yet to access the inside of the sunken yacht, and Mike Lynch is still classified as missing. Other details have emerged in the interim. The accident appears…

Mike Lynch, recently acquitted in HP-Autonomy fraud case, is missing after yacht capsized off Sicily (updated)

Global technology giants are pushing back against attempts by India’s telecom networks to bring internet services under stricter regulation, rejecting arguments that such measures are necessary to create a “level…

US tech giants fight Indian telcos’ bid to regulate internet services, pay for network usage

Pakistani startup PostEx is entering Saudi Arabia as first global market after hitting $21 million ARR in the South Asian nation.

Pakistan’s PostEx to enter new markets, starting with Saudi Arabia

The AI boom is fueling the demand for data centers and, in turn, driving up water consumption. (Water is used to cool the computing equipment inside data centers.) According to…

Demand for AI is driving data center water consumption sky high

The group honking was an unintended consequence of Waymo’s tech.

The Waymo robotaxi honking problem has been resolved for real this time

OpenAI and Anthropic spend billions of dollars a year training models like GPT-4 and Claude, but competitive price dumping is making the business around these platforms rather precarious. Aidan Gomez,…

What margins? AI’s business model is changing fast, says Cohere founder

Hello, and welcome back to TechCrunch Space. Did you hear? Bridgit Mendler will be joining me onstage at this year’s TechCrunch Disrupt to talk all things ground stations. She’s just…

TechCrunch Space: Spending less

What’s the point of chatting with a human-like bot if it’s an unreliable narrator — and has a colorless personality? That’s the question I’ve been turning over in my head…

Gemini Live could use some more rehearsals

Zoom on Monday announced a new single-user webinar feature that caps out at 1 million attendees. The addition comes less than a month after the #WinWithBlackWomen fundraiser for Vice President…

Now a million people can watch you fumble Zoom’s screen-share settings at once

On Sunday, former President Donald Trump posted a collection of memes on Truth Social — the platform owned by his media company — that make it seem like Taylor Swift…

Could Trump’s AI-generated Taylor Swift endorsement be illegal?

Few truly autonomous systems are deployed on the battlefield, but one startup is looking to change that with robotic systems that use cooperative behavior to boost troops’ intelligence and tactical…

Swarmbotics founders grew ‘obsessed with robot swarms’ and now plan to bring them to the battlefield

Former a16z-investor Balaji Srinivasan has booked out an island in Singapore to create his own “Network School.”

Former a16z VC Balaji Srinivasan obtained a private island for his new longevity ‘technocapitalist’ school

The flight tracking company says the misconfiguration exposed customer names, addresses, and pilot’s data, as well as Social Security numbers.

FlightAware warns that some customers’ info has been ‘exposed,’ including Social Security numbers

Over 30% of 7- to 9-year-olds have an X account, according to a new report.

A surprising number of ‘iPad Kids’ are on X, study finds

Apple Podcasts can now be streamed from the web. Apple announced on Monday that its Apple Podcasts app is now available on all major web browsers (Chrome, Edge, Firefox, and…

Apple Podcasts launches on the web

Historic vehicles, flowing champagne and fashion have dominated the events at Monterey Car Week for decades now. But a change is afoot: EVs, tech-centric vehicles, startups and a heavy dose…

From a $2.5 million hyper car to a Spanish track-ready EV, here were the most interesting EVs at Monterey Car Week

The clock is ticking! You’ve got just 5 days left to lock in discounted tickets for TechCrunch Disrupt 2024. Save up to $600 on individual ticket types. This limited-time offer ends…

5 days left to secure ticket savings for TechCrunch Disrupt 2024

General Motors is cutting around 1,000 software workers around the world in a bid to focus on more “high-priority” initiatives like improving its Super Cruise driver assistance system, the quality…

GM cuts 1,000 software jobs as it prioritizes quality and AI

Popular iPad design app Procreate is coming out against generative AI, and has vowed never to introduce generative AI features into its products. The company said on its website that…

Procreate takes a stand against generative AI, vows to never incorporate the tech into its products

ElevenLabs, which develops AI-powered tools to create and edit synthetic voices, is making its Reader app available globally with support for 32 languages.

ElevenLabs’ text-to-speech app Reader is now available globally

AMD is acquiring ZT Systems, which provides compute design and infrastructure for AI, cloud and general purpose computing, for $4.9 billion.

AMD to acquire infrastructure player ZT Systems for $4.9B to amp up its AI ecosystem play

Amazon is considering shifting its payments offerings in India into a standalone app, three sources familiar with the matter told TechCrunch, as the e-commerce giant aims to boost usage of…

Amazon considers moving Amazon Pay into a standalone app in India

Root helps food and beverage companies collect primary data on their agricultural supply chains. 

As CO2 emissions from supply chains come into focus, this startup is aiming at farms

In May, the African fintech processed up to $70 million in monthly payment volume.

Waza comes out of stealth with $8M to power global trade for African businesses