I received a notification last night that someone changed my shipping address on Macys.com and when I visited the website, there was an open order for a PS5 with delivery to a NJ address.

After logging into Macy’s I got 43 emails at once to seven different services like “Excalidraw” and “Sportograf” trying to login using a magic link.

At this point was was pretty nervous so I checked my main email security. Sure enough, there have been repeated login attempts under my account going on every few minutes for weeks.

I also saw there was an attempted login to my cellphone or home internet company.

I use 2FA, authenticators, etc. Basically what else should I be doing? Is there any way to be more preventative? I really don’t wanna chuck this email but it is possible that may be the safest recourse. I do use this email for almost 300 different accounts to various things though.

8/23 update

So I received this suspicious email as a “note to self” from Microsoft in my junk folder. It says it’s from my address but additionally says it’s an “unverified server.” I am leery of it being legit but it is oddly timed.

I’ve added the opening text of the email: “Hello pervert, I’ve sent this message from your Microsoft account.

I want to inform you about a very bad situation for you.

However, you can benefit from it, if you will act wisely.

Have you heard of Pegasus? This is a spyware program that installs on computers and smartphones and allows hackers to monitor the activity of device owners. It provides access to your webcam, messengers, emails, call records, etc. It works well on Android, iOS, macOS and Windows. I guess, you already figured out where I’m getting at.”

I’ve received these emails in the past and nothing, but I figure it bears mentioning here cause I was legitimately in a less than secure situation a few days ago.

  • SavvyWolf
    link
    fedilink
    English
    arrow-up
    35
    ·
    3 months ago

    Firstly, probably remove the address from the OP. Don’t want any Lemmy vigilantes getting involved and making a mess of things.

    If you have 2fa enabled, you should be good. Even if they do guess your password, they shouldn’t* be able to log in to your account. Although might still be worth making sure you have a nice strong password anyway. Also, if you have recovery phone numbers or email addresses attached to your email account, make sure they’re secured as well.

    * Assuming that your webmail provider is doing everything correctly, which isn’t always a given if they’re a small one.

      • SavvyWolf
        link
        fedilink
        English
        arrow-up
        29
        ·
        3 months ago

        You’re assuming that the attacker is using their own IP rather than a compromised system owned by someone else.

        Likewise, they might be using someone else’s address with the intent to steal a package from their porch or something.

        It’d be rather silly for a theif to use their own details.

    • otp@sh.itjust.works
      link
      fedilink
      arrow-up
      8
      ·
      3 months ago

      OP probably also needs to secure their mobile account, since the attacker could redirect recovery or MFA SMSs to their own number.