JohnPhilpin
JohnPhilpin

anyone else suddenly being asked by LinkedIN to verify themselves with a Govt ID?

|
Embed
Progress spinner
JohnPhilpin
JohnPhilpin

🔗 Looks Like This Is Likely My Problem

|
Embed
Progress spinner
JohnPhilpin
JohnPhilpin

Yup - confirmed ...

After seeing this log entry, it became clear how the hack was done. The attacker convinced LinkedIn support that he has lost access to the email and need to change it. And somehow, LinkedIn Customer Service agent has accepted the request and changed the email, nicely serving the access of my account to the attacker!

|
Embed
Progress spinner
JohnPhilpin
JohnPhilpin

So - the question is - can I be bothered ...

|
Embed
Progress spinner
pratik
pratik

@JohnPhilpin Yes. I did that a few months ago. Considering it's one of the places where my "real" profile exists, I don't want it compromised. It was done via CLEAR ID verification.

|
Embed
Progress spinner
JohnPhilpin
JohnPhilpin

@pratik this was a hack that bypasses any and all security you do according to the article above. Basically people in their call centers can bypass everything if they believe whoever calls them. Seems like the process is flowing ... earlier today you couldn't get to my profile - but now you can.

|
Embed
Progress spinner
In reply to
pratik
pratik

@JohnPhilpin can’t guard against that kinda stupid safeguards

|
Embed
Progress spinner
JohnPhilpin
JohnPhilpin

@pratik all back up and no damage done - other than loss of time.

|
Embed
Progress spinner