Could a messaging account have been compromised?¶
Unexpected messages or unfamiliar linked devices may indicate that someone else accessed the account.
Evidential caution: that all activity on the account was authorised by the legitimate user.
What this means¶
Compromise may occur through stolen credentials, phishing, reused passwords, malicious software, stolen authentication codes, SIM swap, linked-device abuse or temporary access to an unlocked device.
Signs may include new-device alerts, unfamiliar sessions, changed recovery details, password resets, unusual locations, unexplained message activity or the loss of account access.
Also consider whether the account was shared knowingly rather than compromised.
In reports, describe the evidence supporting or weakening the compromise explanation.
Where the issue is disputed, identify what additional evidence would strengthen or weaken the attribution.
Where the issue is disputed, identify what additional evidence would strengthen or weaken the attribution.
What to check or do next¶
- Preserve security emails, notifications, login records, linked-device lists, recovery changes and the timing of disputed communications.
- Do not immediately reset passwords or revoke sessions before documenting the current state unless operational risk requires urgent action.
- Compare provider records, device evidence, IP activity, account-security history and the user’s conduct.
- Preserve the source and collection method so another investigator can test the same conclusion.
- Preserve the source and collection method so another investigator can test the same conclusion.
Evidential limits¶
A claim of compromise is an alternative explanation, not an automatic conclusion. Test whether the suspicious session existed at the relevant time and whether it could perform the disputed action.
Operational takeaway
Preserve and test account-security, session and device evidence whenever compromise is a realistic explanation for disputed messaging activity.