Your Twilio Authy Number Gave Attackers a Key to Your Accounts
HEROIC analysts identified the Twilio Authy breach on July 10, 2024, exposing the phone numbers of 33,419,947 users of the widely trusted two-factor authentication app. The compromised data was extracted through an unauthenticated API endpoint in Twilio's infrastructure, then circulated on underground forums. Although no passwords or financial data were included, a breach of this scale targeting an authentication application carries consequences that extend far beyond what the single exposed field suggests.
Why This Is Dangerous
Phone numbers tied to an authentication app are not ordinary contact details. Attackers who obtain this dataset know these numbers are actively linked to account security workflows. With 33 million verified, active phone numbers in hand, threat actors can mount targeted SIM-swapping campaigns, social engineering attacks, and smishing operations designed specifically to bypass the two-factor authentication protecting victims' most sensitive accounts. The data's value comes not from what it contains in isolation, but from what it unlocks when combined with credentials available in other breaches.
What Was Exposed
- Phone Number
Why This Matters
The Twilio Authy breach matters because it degrades the security layer millions of people depend on. Criminals who match these phone numbers against credential databases from other leaks can attempt account takeover on banking, email, and social media platforms where SMS-based two-factor authentication is the primary defense. Victims face identity theft, financial fraud, and unauthorized account access. The breach also signals to attackers exactly which phone numbers belong to security-conscious users, making them higher-value targets for sophisticated social engineering.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a structured data store, typically by exploiting an unprotected endpoint, a misconfigured API, or a software vulnerability. In this case, Twilio's unauthenticated endpoint allowed external queries without requiring valid credentials, enabling the bulk extraction of user records. Once data is exfiltrated, it is compressed and traded on dark web forums, often within hours of extraction. The compromised organization may not detect the intrusion until the data surfaces publicly.
Check If You Are Affected
HEROIC's free identity scanner checks your email and personal data against more than 400 billion exposed records, including breach datasets like this one. If your phone number was registered with Twilio Authy, run a scan now to understand your full exposure and take immediate action to secure your accounts.
Breach Breakdown
33,419,947 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds