Can an attacker or unauthorised user add a linked device?¶
An account holder may deny sending messages even though the account shows linked-device activity.
Evidential caution: that every linked device was knowingly added by the legitimate user.
What this means¶
An attacker who gains temporary access to the phone, authentication process or account may be able to add a new linked device or browser session.
Once linked, that device may read or send messages, receive synchronised content and remain active after the initial access ends.
This can explain activity that continues while the primary phone is back with the account holder.
Consider whether the account holder scanned a linking code, approved a prompt or had the device unlocked by another person.
A linked device may also be legitimate but later used without authority.
Where the position is unclear, compare device records, provider metadata and the account’s security history.
What to check or do next¶
- Preserve linked-device lists, security alerts, verification messages, login events and the timing of suspicious activity.
- Do not immediately revoke the session before documenting it unless operational risk requires urgent action.
- Look for unfamiliar device names, locations, IP activity, browser sessions and changes to account-security settings.
- Preserve the original source and collection method so another investigator can test the same conclusion.
- Preserve the original source and collection method so another investigator can test the same conclusion.
Evidential limits¶
Account compromise remains an alternative explanation, not an automatic conclusion. Test it against device possession, session history and wider conduct.
Operational takeaway
Treat unfamiliar linked devices as potential unauthorised access routes and preserve the linking, session and security evidence before revoking them.