Nope - if you hit "forgot password" it sends a pin and if you get the pin you can change the password.
If you do this on the BTID then you can change the mobile number associated with the account.
They are not entering usernames and passwords, just username and forgot password then trying the luck/brute force to get the pin right.
This is why pin should be at least 8 digits.
Ok I got it.. thanks for clarifying.. yeah a 4 pin code isn't the strongest is it..
Yes, that is possible if they already have your username and password but they would still be in the position of having a 1 in 10,000 chance of getting it right and each attempt would be 1 in 10,000.
It is more likely they are using the "Forgotten password" facility to try to reset your password to something they know. If that is the case they still only have a 1 in 10,000 of getting it right each time they try.
Edit: Your concern is only true if the OTP is a static number that is the same each time. In all the OTP systems I know, it is not. It resets after each attempt, generating a new number.
I'm up to about 300 texts received in 24 hours - and as was put by another user, there are many texts with the same 4 digit pin and not in sequential texts - so this is also a little strange as would suggest the random generation is not so random (but that a guess on my part)
OK, that might work, but if you are going put that much effort into hacking an account there needs to be some significant gain when you get in. I just don't see the average joe's email account being worth that effort.
I'll leave you to it, anyway. I was only trying to offer some reasurance.
Is there any solution for this?
I’m having the exact same attack, between 500-1000 texts and emails within the last 12 hours, with the last batch of around 250 just 2 hours ago.
I’ve reported it to BT, but at this point it feels like just a matter of time until they get in.
They got into my account overnight - I was online as they did it and lost access to my email and BTID but I managed to request pin before they changed the telephone number on my account (although my BTID page is still not working)
The issue is they get access to email and then the BTID reset sends the passcode to that same email which allows them to change all the details
I don't know if my account is compromised or not and BT phone lines not open yet.
It's pure negligence on BTs part - they knew of this vulnerability and have done nothing