Skip to content
>_ITDITDWeb Security Platform
tag

account takeover

3 articles with this tag

2026-09-26

Spam from your own email address: usually a forged sender, and how to tell if you were hacked

Most spam that arrives 'from' your own address is a forged sender field; your account was never touched. Japan's IPA and JC3 have both warned about extortion emails made to look like this, and IPA says its help desk has not seen a single case of footage actually being released. This site's view: the sender can write anything in the From field. Before you panic, spend five minutes on three places — Sent, sign-in history, forwarding rules. And if the email quotes a password you still use, change it today.

2026-09-05

Password reset design flaws: 5 ways accounts get taken over despite strong login, and how to fix them

A reset flow is a mechanism for letting someone who does not know the password set a new one — which makes it an authentication path in its own right. Harden the login all you like: if reset is weak, reset is your real authentication strength. Five failure shapes: guessable tokens, tokens that never expire, links that live on in a mailbox, links whose destination can be set from outside (Host header), and responses that reveal whether an account exists. The key implementation step is separating what the guidance requires from the numbers it leaves to you.

2026-07-07

7pay Fraud (2019) — How a Payment App With No 2FA Got Taken Over

Account takeovers began the day after launch; ~808 users lost ~¥38.6M. The core failure was authentication design: (1) no two-factor authentication, so login needed only ID + password, and (2) a password reset that could send the new password to an email address other than the registered one — so fragments of personal data were enough to hijack an account. Defend by requiring 2FA on sensitive actions, restricting password reset to registered channels, detecting and locking credential-stuffing, and having auth flows reviewed by a second set of eyes before launch.