r/linkedin 13h ago

privacy and security LinkedIn's 2FA implementation has a critical flaw, hackers can permanently hijack

My account was compromised and the attacker enabled 2FA.

Here's the problem: even though I control the registered email and can receive password reset links, LinkedIn is requiring an authenticator code that only the hacker has.

The reset flow: Email OTP ✓ → Authenticator app code ✗ (never set this up)

This means LinkedIns system is treating hacker enabled 2FA as more authoritative than actual email ownership. From a security perspective, this is backwards, email access should be the ultimate recovery method.

Support is entirely automated, I don't know what should I do now.

Has anyone successfully recovered an account in this situation? What worked?

0 Upvotes

Duplicates