logo

Millions of people imperiled through sign-in links sent by SMS

ID: 62c50c3b-50a6-5662-a298-ef52fc77feb8

STIX ID: report--62c50c3b-50a6-5662-a298-ef52fc77feb8

Feed Name: Ars Technica Security

Threat Score
72/100

Date Published: 2026-01-21

Date Updated: 2026-04-19

Author: Dan Goodin

...
...

Researchers analyzed public SMS gateways and collected 322,949,000 unique SMS-delivered URLs from over 33 million texts, finding that tokenized authentication links from 177 services (originating via 701 endpoints) exposed critical personally identifiable information—including SSNs, dates of birth, bank account numbers, and credit scores. The study warns that weak link-based SMS authentication is trivially exploitable at scale using consumer-grade hardware and basic web security knowledge, though ethical constraints limited the ability to measure the full scope of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.