<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>This topic</title>
    <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402410#M116419</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/339578"&gt;@noddy1&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;The fact that someone added an auto forward rule to my email tells you a lot!&amp;nbsp;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;That is the first time you mentioned that! I don't have a crystal ball.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;noy sure who you work for, but your barking up the wrong tree fella.&amp;nbsp;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;What has who I work for got to do with you. I will say however I do not nor have I ever worked for BT or EE&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I keep getting hacked and BT is the blame for their novice security measures!&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;If you say so!&amp;nbsp; I'll leave you to it.&lt;/FONT&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Aug 2024 17:24:06 GMT</pubDate>
    <dc:creator>gg30340</dc:creator>
    <dc:date>2024-08-23T17:24:06Z</dc:date>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402342#M116401</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is happening to me over and over again, they keep getting in bypassing any 2FA requirements, I've been pulling my hair our constantly resetting my account, I changed my BT ID from my email, and now I don't even get notified when they update the email address password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BT are an absolute joke for such a large technology company, they have no idea about security!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 09:19:39 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402342#M116401</guid>
      <dc:creator>noddy1</dc:creator>
      <dc:date>2024-08-23T09:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402364#M116402</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="color:var(--ck-color-mention-text);"&gt;&lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/339578"&gt;@noddy1&lt;/a&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sorry you're details are being changed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have an alternative email address registered for your BT ID?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you reported this to our Broadband team to get looked into?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Leanne.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 11:32:28 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402364#M116402</guid>
      <dc:creator>Leanne_T</dc:creator>
      <dc:date>2024-08-23T11:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402369#M116404</link>
      <description>&lt;P&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/339578"&gt;@noddy1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have moved you onto your own thread so that you get answers regarding your problem and not confused with OP of the other thread you posted on.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:03:03 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402369#M116404</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2024-08-23T13:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402377#M116410</link>
      <description>&lt;P&gt;I have spoked to BT probably nearly 15 times over the last couple of months! nobody can tell me why it keeps happening, your internals clearly know there is an issue as many support staff say they know about an issue.&lt;/P&gt;&lt;P&gt;BT are unable to offer any additional security for a flaw in their 2FA system, I mean if people can bypass any security and change a password, they have a major issue, either internally or with your system!&lt;/P&gt;&lt;P&gt;before you say it, it has nothing to do with my systems, they are all protected by Firewalls, malware and virus scanners (Both separate and leading technologies).&lt;/P&gt;&lt;P&gt;i have waster so many hours of my time and it's actually causing me stress-related illnesses, I have been with BT for over 10 years so half my life is secured with the email, so many days of work to undo it all.&lt;/P&gt;&lt;P&gt;But looks like I have no choice but to finally move provider!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:20:23 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402377#M116410</guid>
      <dc:creator>noddy1</dc:creator>
      <dc:date>2024-08-23T13:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402378#M116411</link>
      <description>&lt;P&gt;How many devices do you use to access your email account?&lt;/P&gt;
&lt;P&gt;Do you have any "Password Manager" programs on your device?&lt;/P&gt;
&lt;P&gt;Do you use an email client or a web browser to access your email?&lt;/P&gt;
&lt;P&gt;Do you use a VPN?&lt;/P&gt;
&lt;P&gt;Do you use anything such as "Mail Washer" on your device(s)?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 13:26:49 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402378#M116411</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2024-08-23T13:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402386#M116412</link>
      <description>&lt;P&gt;I have 3 devices, all with mallwarescanner and norton, I haven't got a VPN anymore, but that is not how they are getting in even if I didn't, because they can change my Pword without ever sending a PIN or using 2FA, so it's some BS bypass they have somehow, nowt to do with a hack as I can't even change my own pWord with receiving a PIN first&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I have passwordvaults, if they were able to access them then I would have major issue, but that is defo not the case! just my BT mail&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 14:25:40 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402386#M116412</guid>
      <dc:creator>noddy1</dc:creator>
      <dc:date>2024-08-23T14:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402400#M116415</link>
      <description>&lt;P&gt;The questions were asked not to find out how you were hacked they were asked to see if you had been hacked.&lt;/P&gt;
&lt;P&gt;Just because you have been locked out of your account does not necessarily mean you have been hacked.&lt;/P&gt;
&lt;P&gt;How do you know that your account has been hacked and not just locked until you change your password for some reason?&lt;/P&gt;
&lt;P&gt;It could simply be that your account has been locked because the BT servers suspect that somebody or some thing has been attempting unauthorised access your account.&lt;/P&gt;
&lt;P&gt;I note that you are not using one but for instance using a VPN can be seen as such because it uses IP addresses from various places around the world some of which can be black listed.&lt;/P&gt;
&lt;P&gt;Using multiple devices that are all set to poll for email at the same period can be seen as multiple attempts to access the email account especially if the devices are not in the same place and if using a blacklisted IP address.&lt;/P&gt;
&lt;P&gt;It could be that somebody with a similar email address with just one digit different has been trying to change their password and has been mistakenly using the&amp;nbsp; wrong email address and that would cause your account to be locked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 16:15:17 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402400#M116415</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2024-08-23T16:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402405#M116418</link>
      <description>&lt;P&gt;The fact that someone added an auto forward rule to my email tells you a lot!&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;noy sure who you work for, but your barking up the wrong tree fella.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I keep getting hacked and BT is the blame for their novice security measures!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 16:58:15 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402405#M116418</guid>
      <dc:creator>noddy1</dc:creator>
      <dc:date>2024-08-23T16:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402410#M116419</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.bt.com/t5/user/viewprofilepage/user-id/339578"&gt;@noddy1&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;The fact that someone added an auto forward rule to my email tells you a lot!&amp;nbsp;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;That is the first time you mentioned that! I don't have a crystal ball.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;noy sure who you work for, but your barking up the wrong tree fella.&amp;nbsp;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;What has who I work for got to do with you. I will say however I do not nor have I ever worked for BT or EE&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I keep getting hacked and BT is the blame for their novice security measures!&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;If you say so!&amp;nbsp; I'll leave you to it.&lt;/FONT&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:24:06 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402410#M116419</guid>
      <dc:creator>gg30340</dc:creator>
      <dc:date>2024-08-23T17:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402414#M116421</link>
      <description>&lt;P&gt;No need to angry bro, I’m the one on the end of a hack when they have managed to try and changed password for financial accounts..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it’s BT’s fault for implementing sub par security&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2024 17:30:18 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402414#M116421</guid>
      <dc:creator>noddy1</dc:creator>
      <dc:date>2024-08-23T17:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: Hacked email and password change - Bypassed 2 factor authentication</title>
      <link>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402549#M116440</link>
      <description>&lt;P&gt;If you scroll down the list of community messages, BT's failure with 2FA seems to be a VERY common theme and it seems most customers have same issues and concerns over BT's unsophisticated security platform.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our "MY BT" Account was compromised a month ago. A scammer fooled BT using online Chat and providing answers to very simple security questions (easily found on Electoral role or more likely already on Internet) such as DoB, last 4 digits of bank account, BT acct No etc. Our account and email was compromised, emails download and we had a £2k fraudulent transaction on credit card. Luckily, being in IT Security, I was able to shut things down quickly - once I'd found out I'd been hacked.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recreated what the scammer/hacker did and using a friends MY BT account, I was able to answer 4 simple security questions and change the mobile number and ID.&amp;nbsp; I was never challenged with 2FA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've told BT their 2FA is not working, 3 or 4 times. I've asked them why the scammer was not challenged with 2FA at time of changing our ID and mobile number. I'm waiting for the answer. In the meantime, I record once a week when I log on to see if 2FA prompt's - it doesn't. I record changing passwords to see if 2FA prompt's - it doesn't.&lt;/P&gt;&lt;P&gt;Another tread implies BT have a new 2FA (from Feb 2024) which "&lt;SPAN&gt;is risk based and uses several factors to decide when to make a 2FA prompt". So I've tried clearing all history and cookies and using different browsers. No 2FA prompt. I've tried different computers - no 2FA prompt. So I got a friend 100 miles away to log onto our MT BT Account - no 2FA prompt. I got another friend to log on to our MY BT account via his mobile, ensuring wifi was turned off - still no 2FA prompt.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It is shameful of BT. They seem to be in complete denial. They have 25 million consumer customers. All at risk because the BT 2FA does not work.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Aug 2024 15:19:53 GMT</pubDate>
      <guid>https://community.bt.com/t5/General-email-queries/Re-Hacked-email-and-password-change-Bypassed-2-factor/m-p/2402549#M116440</guid>
      <dc:creator>harveysprimrose2012</dc:creator>
      <dc:date>2024-08-24T15:19:53Z</dc:date>
    </item>
  </channel>
</rss>

