Data Breaches

1,900 Signal user’s phone numbers exposed in Twilio hack

0

Phone numbers of around 1,900 Signal users were exposed in the cyber-attack aimed at Twilio cloud communications company.

Twilio provides phone number verification services for popular end-to-end encrypted messaging service Signal which disclosed that an attacker hacked its network on August 4.

The data belonging to 125 of Twilio customers was exposed after the hackers gained access to one of their employee accounts by sending them text messages with malicious links.

According to an advisory published by Signal, phone numbers of 1,900 Signal users were potentially exposed to the Twilio attacker, who could have attempted to register them to another device. All the other users are assured that their message history, contact lists, profile information, whom they’d blocked, and other personal data remain private and secure and were not affected.

The hacker’s access to Twilio’s customer support console either allowed them to see that the phone number was linked to a Signal account or revealed the SMS verification code for registering with the service. Now the attacker no longer has this access, and the attack has been shut down by Twilio.

The company warns that if an attacker re-registers an account to one of their devices, they would be able to send and receive Signal messages from that phone number.

All affected 1,900 Signal users will be unregistered on all devices and they should register once again.

Signal is now in the process of sending SMS messages to affected users to let them know about the risk.

The impacted users receive a message reading: “This is from Signal Messenger. We’re reaching out so you can protect your Signal account. Open Signal and register again. More info: https://signal.org/smshelp.”

When opening the Signal app, a banner notifying them that their device is no longer registered will also be seen.

The users are advised to turn on the registration lock option, which allows recovering the profile, settings, contacts, and blocked users. The feature can be enabled or disabled only from the device and requires the Signal PIN as an additional verification layer.

Image Credits : PCMag

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Cisco hacked by Yanluowang ransomware gang

Previous article

Musk’s Starlink system hacked with $25 homemade device

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *