Post #2795735
2024-10-26 16:58 UTC
@jschuh@infosec.exchange The link sent via SMS could be the final 2FA verification click needed to approve an account transfer, with the rest having been setup beforehand. If so, the account itself might already have been compromised. (Always assume leaked re-used passwords)
caveat: I have not gone through an Amazon account transfer
Replies (1)
-
@jschuh@infosec.exchange 2024-10-26 18:48
@troed@ioc.exchange Turns out the attacker initiated account recovery over the phone using stolen personal information. The link was the last step, which had to be clicked from a device Amazon already recognized for that account. And the firehose of spam was to bury the alert emails Amazon was sending.