Security Alert: Update to the Authy Android (v25.1.0) and iOS App (v26.1.0) (2024)

Authy | Jul. 01, 2024

Twilio believes that the security of our products and our customers’ data is of paramount importance and when an incident occurs that might threaten that security, we tell you about it.

Twilio has detected that threat actors were able to identify data associated with Authy accounts, including phone numbers, due to an unauthenticated endpoint. We have taken action to secure this endpoint and no longer allow unauthenticated requests.

We have seen no evidence that the threat actors breached Twilio’s systems or that they obtained access to Twilio's systems or other sensitive internal data. As a precaution, we are requesting that all Authy users update to the latest Android and iOS apps for the latest security updates. While Authy accounts are not compromised, threat actors may try to use the phone number associated with Authy accounts for phishing and smishing attacks; we encourage all Authy users to stay diligent and have heightened awareness around the texts they are receiving.

This latest update addresses bug fixes, which include security updates. Please click on the link to download the latest version:

We know the security of our systems is an important part of earning and keeping your trust. We sincerely apologize that this happened. The Twilio Security Incident Response Team will post any updates here if there are any changes. If you have further questions, please reach out to your Technical Account Manager or our Support team.

Notice: If you cannot access your Authy account, we recommend you immediately contact Authy support. One of our specialists will respond to your request, and work with you to get your Authy account back up and running again.

Authy Security

Security Alert: Update to the Authy Android (v25.1.0) and iOS App (v26.1.0) (2024)

FAQs

Is Authy hacked? ›

In a recent cybersecurity incident, Twilio, the developer of the popular two-factor authentication app Authy, confirmed a hack that exposed millions of users' phone numbers.

Is the Authy app safe? ›

Google Authenticator and Authy are both reliable authenticator apps. People looking for a simple and easy-to-use app should get Google Authenticator. The same goes for users who want a higher security level in the two-factor authentication process.

What is Authy Android? ›

Authy is a free mobile app for two-factor authentication, as well as security partner and SMS delivery service of many websites that want to make two-factor authentication work better for their users.

Is twilio authy secure? ›

Using this data, hackers can conduct phishing campaigns to steal login credentials. Twilio quickly addressed the issue and secured the API endpoint. However, they recommend that users update to the latest version of the Authy app and stay vigilant against phishing attempts.

Why would someone use Authy? ›

Authy makes it really easy to use Two-Factor Authentication on your online accounts using your smartphone. We provide you an App that makes it easy for you to keep all your tokens and “just” works for a strong authentication.

What happens if I delete Authy? ›

Your Authy account and all stored data will be permanently deleted in 30 days with no way to recover your account after that time period.

What are the disadvantages of Authy? ›

It does not allow data to be exported. It can delete your TOTP from sites that use Authy integration (e.g., Twitch). It no longer has a Desktop app.

Is Authy discontinued? ›

The Authy Desktop app for Linux, MacOS and Windows reached their End-of-Life on March 19, 2024 and are no longer supported.

Who is behind Authy? ›

Authy, owned by Twilio since 2015, is a popular two-factor authentication (2FA) app that adds an additional layer of account security.

What websites use Authy? ›

Websites using Twilio Authy
#WebsiteTraffic
1actionnetwork.org52%
2valimail.com11%
3africanmanagers.org8%
4upstart.com5%
6 more rows

How do I get rid of Authy? ›

Open the Authy Android app. Tap and hold the desired authenticator account, and then select Remove. A notification window will be displayed advising your account will be deleted in 48 hours. Tap OK to continue.

Does Authy use your phone number? ›

Authy's reliance on phone numbers as part of your identity is not a mere formality; it's a critical component of the app's security architecture. For this reason, it is not possible to use Authy without a phone number.

Can you trust Authy? ›

Both personal users and small or midsize businesses (SMBs) can get secure, scalable password management from Twilio Authy. After testing Twilio Authy's features, I've given Twilio Authy 4.6/5 stars.

Has Authy been breached? ›

At the end of June, hackers claimed to have stolen 33 million phone numbers from Twilio, a major U.S. messaging company.

Can I use Authy with my Google account? ›

To capture the QR code, launch Authy on your device. Click 'Add Account' at the bottom of the screen. You'll be prompted to hold your phone up to your computer to 'Scan QR Code' and capture the QR code provided by Google. Once the QR code is captured, Authy will display your Google account with the appropriate icon.

What is the security issue with Authy? ›

In a post on a well-known hacking forum, the hackers known as ShinyHunters claimed responsibility for hacking Twilio and obtaining the phone numbers of 33 million users. Attackers then identified Authy customers' phone numbers and other data through an unauthenticated endpoint, which has since been secured.

How secure is Authy backup? ›

We encrypt your data, and only decrypt on the devices using a password only you know. (and must not forget!)

Top Articles
This Is Why Four-Leaf Clovers Are Considered Lucky
6 Steps To Installing PIP on Windows for Python
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Van Hayes

Last Updated:

Views: 6644

Rating: 4.6 / 5 (66 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Van Hayes

Birthday: 1994-06-07

Address: 2004 Kling Rapid, New Destiny, MT 64658-2367

Phone: +512425013758

Job: National Farming Director

Hobby: Reading, Polo, Genealogy, amateur radio, Scouting, Stand-up comedy, Cryptography

Introduction: My name is Van Hayes, I am a thankful, friendly, smiling, calm, powerful, fine, enthusiastic person who loves writing and wants to share my knowledge and understanding with you.