Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Data Leak

The Passwordless Trap: How SMS “Magic Links” Are Leaking Your PII

by Nam Phong · January 23, 2026

Accessing a personal account has evolved into a triviality, often requiring a mere solitary click upon a link dispatched via SMS. While such a mechanism is ostensibly convenient, swift, and devoid of the burden of passwords, researchers have unveiled that this very simplicity constitutes a formidable peril to the privacy of millions worldwide.

The inquiry demonstrates that digital platforms employing authentication via links and codes delivered through text messages are systematically exposing users to the specters of fraud, identity theft, and the exfiltration of sensitive data. This phenomenon permeates mundane services, including recruitment portals, insurance premium calculators, pet-sitting platforms, and academic tutoring services. In lieu of traditional credentials, users are prompted to provide a telephone number, subsequently receiving a “magic link” or numerical code to facilitate entry.

The crux of the vulnerability lies in the inherently precarious architecture of these links. Scientists identified over 700 technical touchpoints through which SMS dispatches are orchestrated on behalf of 175 disparate services. A significant plurality of these platforms utilize predictable, easily decipherable tokens within their URLs. By merely altering a few characters in the address, an adversary can commandeer a stranger’s account. In practical demonstrations, researchers were able to scrutinize the private dossiers of other users—including partially finalized insurance applications—and, in certain instances, theoretically execute actions on their behalf.

Some services relied upon such rudimentary code combinations that they were susceptible to automated brute-force attacks. In other scenarios, the SMS link provided unfettered access to data without any secondary verification whatsoever. Furthermore, many of these links remained valid for years after their initial dispatch, drastically amplifying the window for unauthorized access.

The situation is further exacerbated by the fact that SMS communications lack encryption. Historically, in 2019, specialists discovered exposed databases containing millions of archived messages, harboring login links, names, physical addresses, financial applications, and other confidential telemetry. The current study aggregated over 322,000 unique links from a corpus of 33 million messages sent to more than 30,000 numbers. In 701 instances, the services involved were found to reveal critical personally identifiable information (PII): dates of birth, bank account numbers, credit scores, and even social security numbers. 125 services were identified as being vulnerable to mass token enumeration due to anemic generation algorithms.

The authors of the study emphasize that the true magnitude of this crisis is likely far more expansive. Their observations were limited to public SMS gateways—platforms where individuals receive messages on temporary numbers to preserve anonymity. Such gateways offer only a fragmented glimpse into the ubiquity of this insecure authorization paradigm.

The researchers assert that the primary burden of responsibility rests with the service providers rather than the end-users. Protection is difficult for individuals to achieve, as the list of vulnerable platforms includes prominent, reputable corporations with millions of clients. Users are left with few options beyond reporting these deficiencies and deleting their data upon realizing the inadequacy of the protection.

To be sure, the concept of “magic links” is not inherently malevolent. When implemented with cryptographically robust tokens, singular usage constraints, and strict temporal expirations, the mechanism can be relatively secure. Some platforms utilize similar methods via email, where the link is further fortified by the two-factor authentication (2FA) protecting the inbox itself. However, for major financial institutions and primary communication platforms, such methods are deemed unacceptable due to the sheer volume of data at stake and the complexities of account recovery.

The study ultimately reveals that user convenience increasingly triumphs over security. Of the 150 companies contacted by the researchers, a mere 18 offered a response, and only seven implemented substantive remediations. As the practice of SMS-link authentication continues to proliferate, users must recognize that these messages are not merely gateways to their accounts, but potential conduits for the leakage of their most sensitive information—a problem that, given the industry’s inertia, is unlikely to dissipate in the near future.

Related coverage

  • AI Doxxing Tools: Extremist Forums Automate Harassment
  • ModHeader Extension Removed for Hidden Tracking
  • Bits of Gold Warns Customers of Data Breach via Third-Party Support System
  • Microsoft Azure Directory Leak Exposes Global Corporations
  • French Tax Agency Breached Twice, ZeroBytes Claims Sale of 678,000 Records

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: Account TakeoverCybersecurity 2026data privacyInfosecMagic LinksPasswordlessPII LeakSMS AuthenticationSMS SecurityToken Enumeration

Follow:

  • Next story Smartphone as Spy: How Jordan Uses Cellebrite to Crush Digital Dissent
  • Previous story 48 Hours to Chaos: SmarterMail Admin Bypass Exploited After “Secret” Patch

  • Recent Posts
  • Popular Posts
  • Tags
  • T-Mobile Salt Typhoon cyberattack network cable cut China telecommunications hack

    Cybercriminals

    T-Mobile Staff Physically Cut a Cable to Stop Salt Typhoon Intrusion

    August 21, 2026

  • Ransom Busters extortion scheme ransomware affiliate double extortion GuidePoint

    Malware

    “Ransom Busters” Scheme Likely Run by Ransomware Affiliates Themselves, GuidePoint Says

    August 21, 2026

  • Mabna Institute Iranian hackers cyber theft campaign targeting global universities and intellectual property

    Cybercriminals

    17 Iranians Indicted for Massive Cyber Theft Campaign

    August 21, 2026

  • C2Looper backdoor malware execution flow and GitHub command and control structure

    Malware

    C2Looper Backdoor Malware Uses GitHub for C2

    August 21, 2026

  • CVE-2026-33824 Windows IKE vulnerability CISA exploited catalog critical patch

    Malware

    CISA Confirms Active Exploitation of Critical Windows IKE Flaw CVE-2026-33824

    August 21, 2026

  • Snowflake GitHub Actions vulnerability Red Agent Wiz Jira credentials exposure

    Vulnerability

    AI Agent Finds GitHub Actions Bug, Reaches Snowflake’s Internal Jira

    August 19, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach DLL Sideloading Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro