From Zero Click to Full Access

How Phone Link Hijacking Renders SMS MFA Obsolete

First Published: May 2026

A preinstalled Windows feature is quietly turning MFA into a false signal, one that standard investigations are likely missing.

The session was valid. The password was correct. The MFA code was entered correctly. Every control did exactly what it was built to do, and yet your customer ever authorized the transfer.

This attack doesn’t beat MFA by force. It sits beside the victim as every code arrives normally, leaving none of the usual evidence — no phishing link, no SIM swap, no password reuse. The tool that makes it possible ships preinstalled on Windows 11, and is already running on more machines than the controls your customers actually chose to activate.

Our report breaks down:

  • How zero-click Phone Link hijacking works, step by step
  • Why SMS-based MFA can no longer be trusted implicitly as a signal
  • The red flags that may already be hiding in your logs
  • How to close the gap before it becomes a dispute

Download the report