Skip to content
PAY-118 Payments & Banking

Could an attacker add a new payment device or session?

Yes. An attacker who gains sufficient account access may add a new device, create a new session or provision a payment token.

Avoid the dangerous assumption

The dangerous assumption is that activity from a newly registered device automatically proves who the attacker was or how access was obtained.

A new device may be added using stolen credentials, intercepted one-time codes, compromised email, SIM swapping, social engineering, malware or remote access to an existing device.

The provider may record device registration, IP address, session creation, authentication method, contact-detail changes and security alerts.

The attacker may then make payments, change beneficiaries, add cards, redirect payouts, alter contact details, create new recipients or approve transactions.

Preserve the sequence of events around the new device or session.

Request login attempts, password resets, recovery events, one-time-code delivery, device registration, token provisioning, beneficiary changes and transaction records.

Compare the new activity with the account holder’s normal devices, locations and behaviour.

Do not assume that every new device is malicious. Legitimate replacement, travel or additional access may explain it.

Equally, do not focus only on the new device. An attacker may continue using a stolen existing session that appears familiar.

Where security action is needed, preserve device and session evidence before removal where possible.

When reporting, separate the fact that a new access route was created from the attribution of that route to a person.

Operational takeaway

Reconstruct how the new device or session was added, what authentication supported it and what activity followed before attributing control or compromise.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.