Hacker News new | ask | show | jobs
by Cyberspy 2999 days ago
In that case, he must have been logged into Eve's account before he received the email. How did that happen?
1 comments

The parent comment means the scammer case who can set the password back because they are still logged in. Which might be feasible.

But I don't think a scam that relies on you resetting the password and not becoming suspicious is a bit of a stretch.