Hackers abused API to verify Authy MFA phone numbers
bleepingcomputer.com
bleepingcomputer.com
> Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests.
But it is too late, as the threat actors have gotten away with the data.
> We have seen no evidence that the threat actors obtained access to Twilio’s systems or other sensitive data. As a precaution, we are requesting that all Authy users update to the latest Android and iOS apps for the latest security updates.
And this is irrelevant but is drawing attention elsewhere. This 'attack' is adjacent to but not completely related to the app.