Twilio Breach Reveals 1900 Phone Numbers Owned by Signal Users

Share post:

About 1,900 phone numbers of Signal users were potentially exposed in the Twilio’s data breach. Twilio, a cloud communications company, suffered a cyberattack on August 4 that led to the exposure of data belonging to 125 of its customers.

In order to gain access to Twilio’s servers, the hackers used malicious text messages to gain access to the accounts of Twilio employees.

Signal posted a notice informing users of the incident. Signal investigations into the incident revealed that the hacker’s access to Twilio’s customer support console either enabled them to see that the phone number was linked to Signal account or revealed the SMS verification code for registering with the service.

“All users can rest assured that their message history, contact lists, profile information, whom they’d blocked, and other personal data remain private and secure and were not affected. During the window when an attacker had access to Twilio’s customer support systems it was possible for them to attempt to register the phone numbers they assessed to another device using the SMS verification code. The attacker no longer has this access, and the attack has been shut down by Twilio,” Signal said.

Signal pointed out that all affected 1,900 Signal users will be logged off on all devices, and they should go through the registration process on their devices.

The sources for this piece include an article in BleepingComputer.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Google Chrome update essential for Windows users

The latest Chrome update has just been rolled out, bringing the version up to 124.0.6367.78/.79. This update is...

Cyber Security Today, Week in Review for week ending Friday, April 26, 2024

This episode features a discussion on the latest in the Change Healthcare ransomware attack, a vulnerability in an abandoned Apache open source project, the next step in Canada's proposed critical infrastructure cybersecurity law and the future

Cyber Security Today, April 26, 2024 – Patch warnings for Cisco ASA gateways and a WordPress plugin

This episode reports on the malicious plugin worm that refuses to die

Cyber Security Today, April 24, 2024 – Good news/bad news in Mandiant report, UnitedHealth admits paying a ransomware gang, and more

This episode reports on the danger of using expired open-source packages, a tool used by a Russian hacking group and passw

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways