TGTGInsighttelegram intelligenceLIVE / telegram public index
← Global CIO. IT Leaders Community
Global CIO. IT Leaders Community avatar

TGINSIGHT POST

Post #29

@globalcio

Global CIO. IT Leaders Community

Views133Post view count
PostedAug 1608/16/2022, 02:36 PM
Post content

Post content

1,900 Signal users exposed The security breach affected users of the messaging app which is considered to be one of the better secured. Signal claims that an attacker got 1900 numbers but didn’t have access to the profile information, messages, or contact lists. The breach happened on the side of Twilio, a company providing SMS and two-factor verification services for 250 000 customers worldwide. It appears that an attacker gained access to the customer support system, whereby they could send phishing messages asking users to re-register phone numbers. Exposed accounts were transferred to other devices controlled by malefactors. They got access to the Twilio customer due to a well-designed phishing attack that happened last month. Employees received e-mails from the "IT Department" requesting to log in and change their password and linking to a sing-in page look-alike. Leaked credentials were used to get access to Twilio’s internal data. In the security note, Signal claims that an attacker targeted specific users. However, they were hardly able to steal personal information, because it is stored on the devices and the messenger has no access to them. It is also protected with a private Signal PIN code. #CyberSecurity