Twilio Breach Reveals 1900 Phone Numbers Owned by Signal Users

August 17, 2022

About 1,900 phone numbers of Signal users were potentially exposed in the Twilio’s data breach. Twilio, a cloud communications company, suffered a cyberattack on August 4 that led to the exposure of data belonging to 125 of its customers.

In order to gain access to Twilio’s servers, the hackers used malicious text messages to gain access to the accounts of Twilio employees.

Signal posted a notice informing users of the incident. Signal investigations into the incident revealed that the hacker’s access to Twilio’s customer support console either enabled them to see that the phone number was linked to Signal account or revealed the SMS verification code for registering with the service.

“All users can rest assured that their message history, contact lists, profile information, whom they’d blocked, and other personal data remain private and secure and were not affected. During the window when an attacker had access to Twilio’s customer support systems it was possible for them to attempt to register the phone numbers they assessed to another device using the SMS verification code. The attacker no longer has this access, and the attack has been shut down by Twilio,” Signal said.

Signal pointed out that all affected 1,900 Signal users will be logged off on all devices, and they should go through the registration process on their devices.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

June 5, 2026 Security researchers have disclosed a new denial-of-service attack called HTTP/2 Bomb that can overwhelm major web servers more...

May 20, 2026 The Cybersecurity and Infrastructure Security Agency, the arm of the U.S. government tasked with protecting critical infrastructure more...

May 11, 2026 Instructure has restored access to its Canvas learning platform after a cyberattack disrupted service for universities and more...

May 6, 2026 The official White House mobile app for iOS and Android is facing scrutiny after a security researcher more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn