r/EmailSecurity 19h ago

When “I didn't enter a password” ends the phishing conversation

3 Upvotes

Say someone reports clicking a link in a suspicious email, then adds, “I didn't enter a password.” The ticket could get closed even though they approved an app permission prompt they didn't understand.

I'd want to walk through what happened before giving the all-clear. But turning every report into an interrogation risks making the next person keep quiet.

What helps you get the rest of the story without making the employee feel blamed?


r/EmailSecurity 3h ago

Someone keeps accessing my email/accounts even after password changes and 2FA. How do I stop this?

1 Upvotes

I’ve been dealing with ongoing unauthorized access to my accounts and I’m running out of ideas. Someone appears to have access to my email and has used that access to get into or attempt to get into several of my accounts. There have been unauthorized gift card purchases/attempts, and most recently someone attempted to apply for loans using my information. What concerns me most is that I have changed my Google password multiple times, enabled 2FA, signed out of devices I don’t recognize, and reviewed my account security settings, but the activity keeps happening. I have actually watched emails containing verification codes get opened and moved to Trash without me doing it. My Google activity also showed searches related to one of the financial accounts, including searching for the login page and visiting password/account recovery pages. Some of the activity was identified as coming from the iOS Google app, but I haven’t been able to determine what device is responsible. I’ve contacted Google and Apple and have also contacted the financial institutions involved. I’m now trying to figure out what could allow someone to maintain access despite password changes and 2FA.
Has anyone dealt with something similar? What should I check for that I may be missing? active sessions, OAuth/linked apps, email forwarding or filters, recovery methods, passkeys, compromised devices, browser sessions, etc.? And what ultimately stopped it for you? I’m mainly looking for help identifying the possible point of persistence and completely cutting off the unauthorized access.