One of the most trusted 2FA apps Authy suffered from a data breach incident that exposed Authy users' information.
Hackers create extra login devices using user information in order to add all the multi-factor verification codes for the target account.
Twilio’s investigated the attack and contacted the affected users to provide instructions on how to protect their accounts:
-
Check any connected account for ominous activity, and if there is anything off, contact the account provider.
-
Examine all the devices connected to their Authy account, and take any more they don't recognize away.
-
Advised customers to add a backup device and turn "Allow Multi-device" off in the Authy application to avoid the addition of unauthorized devices.
Source: https://securityonline.info/well-known-multi-factor-authenticator-authy-hacked/
"id": "AUT01931822",
"linkid": "authy",
"type": "Breach",
"date": "08/2022",
"severity": "100",
"impact": "6",
"explanation": "Attack threatening the economy of a geographical region"