Skip to content
Skip to main content
Messaging, Social Media & Telecoms Technical Explainer

Can an attacker or unauthorised user add a linked device?

Yes. Someone who can satisfy the service's linking checks may add an endpoint without the account holder's informed authority. The required access might be temporary, while the resulting session can persist.

Linking can outlast initial access

A service may require an unlocked primary device, a scanned code, an approval prompt or account credentials. Once authorised, the new computer, tablet or browser may receive synchronised content and send through the account after the original opportunity has ended.

Unauthorised use can also begin later. A legitimately linked workplace or shared computer might remain signed in and become accessible to someone else. Remote control or stolen session material can complicate the route further.

Test compromise as an explanation

Preserve the linked-device list, link and activity times, verification messages, approval prompts, security alerts, IP-related activity and changes to account settings before revocation where operationally safe. Examine both the primary device and the suspected linked endpoint for corresponding artefacts.

Compare the timing with possession, opportunity and the disputed messages. An unfamiliar device name is not conclusive because labels can be generic or changed; equally, the account holder's denial does not establish compromise.

Report unauthorised linking as a tested alternative unless the combined account, device and contextual evidence supports a firmer conclusion.

The point to remember

A linked session can be created or later used without authority, but compromise requires evidence connecting the linking route, timing and controller.

Reference: MSG-074Messaging, Social Media & Telecoms