
SMS sign-in links expose data for millions, study warns
A new study finds that many services authenticate users via SMS-delivered links or codes, with weak, easily guessable tokens that can be brute-forced or enumerated to access other users’ accounts and view sensitive data. Researchers analyzed 332,000 unique SMS URLs from 33 million texts across 177 services, uncovering 701 endpoints that exposed data and 125 allowing mass enumeration. Only a minority of providers contacted by the researchers have fixed the flaws, underscoring the need for stronger authentication, time-limited links, and multi-factor checks or safer alternatives like email-based magic links.






