Skip to content
Skip to main content
Payments & Banking Technical Explainer

Could an attacker add a new payment device or session?

Yes. Sufficient access can allow an attacker to register an endpoint, establish a session or provision a payment token. The new record shows an access route was created, not who created it or how.

Registration depends on an authentication chain

Credentials, intercepted codes, compromised email, SIM-related attacks, social engineering, malware or remote control may support enrolment. The provider may record login attempts, recovery, code delivery, endpoint registration, IP-related data, token provisioning and security changes.

Existing stolen sessions can also be used without adding anything visibly new.

Reconstruct sequence and consequences

Align authentication and recovery events with the new registration, beneficiary or contact changes, payments and payout. Compare them with established endpoints and normal access, while allowing for legitimate replacement, travel or additional devices.

Where access must be removed, preserve the available session evidence first when safe and proportionate. Report creation of the route separately from attribution or the claimed method of compromise.

The point to remember

Reconstruct the authentication chain and activity around a new endpoint before treating it as evidence of compromise or a particular attacker.

Reference: PAY-118Payments & Banking