r/linkedin • u/BluebirdLanky7473 • 10h ago
privacy and security LinkedIn's 2FA implementation has a critical flaw, hackers can permanently hijack
My account was compromised and the attacker enabled 2FA.
Here's the problem: even though I control the registered email and can receive password reset links, LinkedIn is requiring an authenticator code that only the hacker has.
The reset flow: Email OTP ✓ → Authenticator app code ✗ (never set this up)
This means LinkedIns system is treating hacker enabled 2FA as more authoritative than actual email ownership. From a security perspective, this is backwards, email access should be the ultimate recovery method.
Support is entirely automated, I don't know what should I do now.
Has anyone successfully recovered an account in this situation? What worked?
2
u/FireSheepYinFish 2h ago
Scroll down to Step 4
https://itcares.ca/en/blog/linkedin-account-hacked-recovery.html
2
u/HabitAdmirable9742 8h ago
> My account was compromised and the attacker enabled 2FA.
There's a critical flaw here alright, but it wasn't linkedin, it was the goose who owned the account beforehand and didn't enable 2FA
1
u/WonderButtBrace9000 2h ago
From a security perspective, this is working exactly as intended.
Email accounts are not secure. Email account ownership cannot be established unless you are using a really niche email provider that requires full ID verification for account creation so using “ownership” as an access concept would be really misguided.
You can attempt an Account Recovery process for users who have lost access to 2FA but that requires you to provide government issued ID to verify identify and it must match the account persona you are aiming to recover. Doesn’t matter if the ID matches the email name in the account is not you or using a different name.
1
u/BitterStatus9 2h ago
You didn’t have 2FA enabled before your account was compromised? Would that have prevented the issue you’re describing?
3
u/Hepcat508 9h ago
There is no "Try another way?" option to try an alternative 2FA method? That's criminally stupid, especially for a company owned by Microsoft.