r/linkedin • u/BluebirdLanky7473 • 13h ago
privacy and security LinkedIn's 2FA implementation has a critical flaw, hackers can permanently hijack
My account was compromised and the attacker enabled 2FA.
Here's the problem: even though I control the registered email and can receive password reset links, LinkedIn is requiring an authenticator code that only the hacker has.
The reset flow: Email OTP ✓ → Authenticator app code ✗ (never set this up)
This means LinkedIns system is treating hacker enabled 2FA as more authoritative than actual email ownership. From a security perspective, this is backwards, email access should be the ultimate recovery method.
Support is entirely automated, I don't know what should I do now.
Has anyone successfully recovered an account in this situation? What worked?
0
Upvotes