Signal Confirms Nearly 2,000 Users Exposed in Twilio Data Breach
Signal reveals that attackers accessed the phone numbers and verification codes of approximately 1,900 users due to the recent Twilio phishing breach. The company forces affected users to re-register their devices and strongly advises enabling registration lock.
End-to-end encrypted messaging app Signal confirms that attackers access the phone numbers and SMS verification codes of nearly 2,000 users as a result of the recent Twilio data breach. Malicious actors successfully phish Twilio employees to break into the company's customer support console, exposing sensitive registration data for a small fraction of Signal's massive user base.
The breach allows the attackers to potentially re-register affected phone numbers to different devices, although it does not give them access to message history, contact lists, or profile information. Signal reports that the attacker explicitly searches for three specific numbers and successfully re-registers at least one user's account, enabling the hacker to send and receive messages from that phone number.
In response to the incident, Signal forces all affected users to log out of their current devices and requires them to re-register their accounts on their preferred hardware. The company strongly urges all users to enable the registration lock feature, which prevents account re-registration without a user-specific security PIN, a safeguard that reignites ongoing debates about Signal's reliance on phone numbers for account creation.