share_log

PRIVACY ALERT: Twilio Under Investigation for Data Breach of Over 33 Million Authy MFA Users

PRIVACY ALERT: Twilio Under Investigation for Data Breach of Over 33 Million Authy MFA Users

隐私警报:twilio因超过3300万Authy多因素认证用户数据泄露而接受调查。
PR Newswire ·  07/08 18:34

SAN FRANCISCO, July 8, 2024 /PRNewswire/ -- Schubert Jonckheer & Kolbe LLP is investigating a data breach impacting the private information of 33.4 million users of Authy, a multifactor authentication ("MFA") mobile app developed by Twilio Inc, a California-based cloud communications company.

Schubert Jonckheer & Kolbe LLP正在调查一起数据泄露事件,影响了加利福尼亚州云通信公司Twilio开发的多因素身份验证(”MFA“)移动应用程序Authy的 3,340万 用户的个人信息。

On July 1, 2024, Twilio confirmed that third-party threat actors accessed and downloaded private data associated with Authy accounts, including phone numbers, due to its failure to authenticate an API endpoint.

2024 年 7 月 1 日,Twilio 确认第三方威胁行动者访问并下载了与 Authy 帐户相关的私人数据,包括电话号码,因其未能对 API 端点进行身份验证。

In late June, a cybercrime group called ShinyHunters leaked a text file containing what it claims are 33.4 million private records for Authy users. The file included account IDs, phone numbers, account statuses, and device counts.

6 月底,一个名为 ShinyHunters 的网络犯罪组织泄漏了一个文本文件,其中包含它声称的 Authy 用户的 3,340 万个个人记录。该文件包含帐户 ID、电话号码、帐户状态和设备计数。

According to news reports, the data was compiled by feeding a massive list of phone numbers into the unsecured API endpoint. If the number was valid, the endpoint would return information about the associated accounts registered with Authy.

据新闻报道所述,该数据是通过将大量的电话号码列表输入不安全的 API 端点而编制的。如果号码有效,端点将返回有关使用 Authy 注册的相关帐户的信息。

Although Twilio does not believe that other private data was breached, the stolen phone numbers and related metadata may be used by hackers to conduct phishing, smishing, and SIM swapping attacks. ShinyHunters has already suggested that other threat actors can use the stolen data in combination with other data to conduct additional breaches, including cryptocurrency exploits.

尽管 Twilio 不认为其他的私人数据被泄露,但被盗的电话号码和相关的元数据可能被黑客用于进行网络钓鱼、短信钓鱼和 SIM 交换攻击。ShinyHunters 已经建议其他威胁行动者可以将窃取的数据与其他数据结合使用,进行其他的突破,包括数字货币挖掘行为。

Twilio customers may also be at further risk though another data breach. Twilio has begun sending breach notifications that a third-party vendor's unsecured Amazon Web Services' S3 bucket exposed SMS-related data sent using its networks. In that breach, IdentifyMobile, a downstream carrier of Twilio's backup carrier iBasis, publicly exposed message-related SMS data sent between January 1, 2024, and May 15, 2024. Twilio has informed its customers that some data, including message bodies without login tokens and marketing campaigns, may have been exposed. It could also not rule out the possibility of personal data exposure.

Twilio 的客户也可能通过另一次数据泄露面临进一步的风险。Twilio 已经开始发送泄露通知,第三方供应商未安全保护的亚马逊 Web 服务的 S3 存储桶公开了使用其网络发送的 SMS 相关的数据。在该次泄露中,Twilio 后备载波 iBasis 的下游运营商 IdentifyMobile 公开了 2024 年 1 月 1 日至 2024 年 5 月 15 日之间发送的与消息有关的 SMS 数据。Twilio 已通知其客户,一些数据,包括没有登录令牌和营销活动的消息正文,可能已经被泄露。它还不能排除个人数据泄露的可能性。

If your private information was impacted by this incident, you may be at risk of identity theft, financial fraud, and other serious violations of your privacy. As a result, you may be entitled to money damages and an injunction requiring changes to Twilio's cybersecurity practices.

如果您的个人信息受到此事件的影响,您可能面临身份盗窃、金融欺诈和其他严重的隐私违规行为的风险。因此,您可能有权获得金钱赔偿和要求 Twilio 改变其网络安全实践的禁令。

If you received notification of this data breach or are a current or former user of Authy and wish to obtain additional information about your legal rights, please contact us today or visit our website at .

如果您已收到此数据泄露的通知或者是 Authy 的当前或之前用户,希望获得有关您法律权利的更多信息,请今天联系我们或访问我们的网站。

About Schubert Jonckheer & Kolbe LLP

关于Schubert Jonckheer & Kolbe LLP

Schubert Jonckheer & Kolbe represents shareholders, employees, and consumers in class actions against corporate defendants, as well as shareholders in derivative actions against their officers and directors. The firm is based in San Francisco, and with the help of co-counsel, litigates cases nationwide.

Schubert Jonckheer & Kolbe代表股东、员工和消费者针对企业被告的集体诉讼,以及代表股东对其官员和董事提起的衍生诉讼。该律所总部位于旧金山,并与协助诉讼的律师一起全国打官司。

Contact
Amber L. Schubert
Schubert Jonckheer & Kolbe LLP
[email protected]
Tel: 415-788-4220

联系人
Amber L. Schubert
Schubert Jonckheer & Kolbe LLP
[email protected]
电话:415-788-4220

SOURCE Schubert Jonckheer & Kolbe LLP

消息来源:Schubert Jonckheer & Kolbe LLP

声明:本内容仅用作提供资讯及教育之目的,不构成对任何特定投资或投资策略的推荐或认可。 更多信息
    抢沙发