Breach Debrief: Twilio’s Authy Breach is a MFA Wakeup Call

Originally published by Adaptive Shield.Inside the HackEarlier this week, Twilio issued a security alert informing customers that hackers had exploited a security lapse in the Authy API to verify Authy MFA phone numbers. Hackers were able to check if a phone number was registered with Authy by feeding the number into an unauthenticated API endpoint. Using this data, hackers can conduct phishing campaigns to steal login credentials.Twilio quickly addressed the issue and secured the API endpoin…