Unsolved
10 Elder
•
45.2K Posts
0
89
March 4th, 2024 20:52
Database leaked two-factor authenication codes
Two-factor authentication (2FA) codes are sent via SMS text messages you receive when trying to log into web sites with 2FA enabled.
A tech company that routes millions of 2FA text messages around the world every day had an unsecured database which was spilling one-time security codes and may have allowed hackers to access Facebook, Google, TikTok accounts.
The database currently has monthly 2FA logs dating back to July 2023, but -stupidly- didn't keep logs of database access. So they don't know who or when it may have been accessed by outsiders.
The database is now secured after a security expert found it on the internet and, with additional help, was able to identify its owner.
You may want to change passwords on accounts where you recently needed 2FA to log in because it's not clear which sites, aside from the ones listed above, use that company's 2FA text message service.
Read more here...
