In the last few days, the encrypted messaging platform, ‘Signal’ confirmed a variety of their customers fell victim to the phishing attack on Twilio. It is estimated that 1,900 were affected by the breach via phone number and SMS verification links to “reset passwords” on a phony Twilio link. By posing as Twilio’s IT dept, the hackers were able to obtain victim’s login credentials. Unfortunately, it is still unclear who was behind this attack. Cloudflare also revealed they were subjected to a phishing attack around the very same time as Twilio, but was not breached as an end result owing to the corporation-vast use of hardware-centered, FIDO2-compliant multi-factor authentication (MFA) keys.


More

Gizmodo: Here’s the Best Way to Protect Your Accounts From Hacker Takeovers

Gizmodo reports on a recent Google study showing that FIDO security keys are the most…

Read More →

The Inquirer: Microsoft goes all in on FIDO2 as it dreams of a password-free future

Microsoft has been working towards killing the password for some time, but now the dream…

Read More →

The Next Web: Passwordless web gets a boost from Windows Hello FIDO2 certification

The Next Web reports that Windows Hello, Microsoft’s passwordless authentication method that allows Windows 10…

Read More →