Hacker News new | ask | show | jobs
by dist-epoch 1022 days ago
Interesting hack, but it wouldn't explain the case where you receive multiple such resets emails.
2 comments

Well.. I have a theory. Maybe the threat actors are sending the recovery email with the hopes that the target does not engage. Then, the threat actor can indicate that they "no longer have access to this email address" to force recovery to an alternate address. Then, perhaps they have gained access to some people's old alternate email addresses either through credential stuffing or recreating deleted email accounts. If so, the TA can finish the reset and take over the account.
Could be multiple different actors doing it
Or some runaway script.