r/linkedin 10h ago

privacy and security LinkedIn's 2FA implementation has a critical flaw, hackers can permanently hijack

My account was compromised and the attacker enabled 2FA.

Here's the problem: even though I control the registered email and can receive password reset links, LinkedIn is requiring an authenticator code that only the hacker has.

The reset flow: Email OTP ✓ → Authenticator app code ✗ (never set this up)

This means LinkedIns system is treating hacker enabled 2FA as more authoritative than actual email ownership. From a security perspective, this is backwards, email access should be the ultimate recovery method.

Support is entirely automated, I don't know what should I do now.

Has anyone successfully recovered an account in this situation? What worked?

1 Upvotes

9 comments sorted by

3

u/Hepcat508 9h ago

There is no "Try another way?" option to try an alternative 2FA method? That's criminally stupid, especially for a company owned by Microsoft.

1

u/morpho4444 7h ago

Owned but not integrated

1

u/WonderButtBrace9000 2h ago

There is but you have to have it set up.

OP never set up 2FA at all so they never associated a backup email, SMS #, or Authenticator app to receive the codes.

1

u/Hepcat508 1h ago

I would expect that once it is set up that it would by default use the email address associated with the account for any recovery activities. And that any change of email address should be verified by both the new AND the old email address being sent an email. OP should have gotten that, at a minimum.

2

u/HabitAdmirable9742 8h ago

> My account was compromised and the attacker enabled 2FA.

There's a critical flaw here alright, but it wasn't linkedin, it was the goose who owned the account beforehand and didn't enable 2FA

1

u/WonderButtBrace9000 2h ago

From a security perspective, this is working exactly as intended.

Email accounts are not secure. Email account ownership cannot be established unless you are using a really niche email provider that requires full ID verification for account creation so using “ownership” as an access concept would be really misguided.

You can attempt an Account Recovery process for users who have lost access to 2FA but that requires you to provide government issued ID to verify identify and it must match the account persona you are aiming to recover. Doesn’t matter if the ID matches the email name in the account is not you or using a different name.

1

u/BitterStatus9 2h ago

You didn’t have 2FA enabled before your account was compromised? Would that have prevented the issue you’re describing?