Could a payment application remain active on several devices?¶
Yes. A payment application or account may remain active across several phones, tablets, browsers or other devices.
Avoid the dangerous assumption¶
The dangerous assumption is that possession of one logged-in device proves that all account activity came from that device.
Some providers permit multiple registered devices or simultaneous sessions.
An old phone, replacement device, tablet, browser or watch may remain authorised until it is removed or the session expires.
A family member, employee or offender may also have access through another device.
Relevant records may include registered-device lists, session IDs, login history, IP addresses, token information, authentication events and device-removal records.
A transaction notification appearing on one phone does not prove that phone initiated the payment. Notifications may be synchronised to several devices.
Likewise, a payment made on one device may be approved or authenticated on another.
Preserve the provider’s device and session records before passwords are changed or access is revoked.
Compare transaction timestamps with logins, device activity and authentication events.
Ask whether the provider distinguishes registered devices, active sessions and notification devices.
Do not assume that the newest device is the attacker’s device or that an old device is inactive.
A user may legitimately maintain several devices. The relevant issue is which device and session participated in the activity under investigation.
When reporting, identify which devices were associated with the account and state what evidence links a particular transaction to one of them.
Operational takeaway¶
Treat every registered device and active session as a possible access route and use provider records to determine which device participated in the transaction.