问HN:X账户再次被黑客入侵——当攻击者更改邮箱时为什么没有收到邮件?这是怎么回事?

4作者: hadaoaxb大约 1 个月前原帖
大家好, 我正在试图弄清楚这件事情是如何发生的,希望这里有人能对X(Twitter)的系统运作有更多了解。 第一次,我公司的X账户在两周前被黑客攻击。这完全是我的错——我点击了一个网络钓鱼邮件,泄露了密码,甚至上传了一些公司文件和我的身份证明。但在12小时后,X的客服帮助我恢复了账户,我更改了密码,启用了所有的双重身份验证选项(尽管我一开始就启用了,但黑客绕过了这些措施),他们告诉我已经撤销了所有会话。从那以后,我只通过官方移动应用登录,其他员工只是被授权,并没有登录权限。 第二次,发生在两周后(昨天)——我突然被踢出了应用,所有团队的授权成员也失去了访问权限,当我尝试重新登录时,系统却提示找不到我的邮箱。但这次,我没有收到任何来自X的通知,说明邮箱已被更改,和第一次的情况完全不同。 我的邮箱是完全安全的——没有任何被入侵的迹象,也没有新的登录会话。 SIM卡也没问题,没有新的登录。我自从第一次网络钓鱼攻击后,没有点击任何可疑链接,也没有安装任何新应用。 我在想: 1. 是否有人可以在X账户上更改邮箱,而不会触发通知到原邮箱? 2. 如果有人在联系支持时声称原邮箱被入侵,X是否会在两周后抑制这些通知? 如果有人见过类似的情况或知道后台系统是如何运作的,我非常想听听。我仍在等待X的支持,但这件事真的让我很困扰。
查看原文
Hey folks, Hey everyone, I’m trying to figure out how this happened and hoping someone here might know more about how X’s (Twitter) system works.<p>First time, my company’s X account was hacked 2 weeks ago. Totally my fault — I clicked on a phishing email and gave them the password and even uploaded some company documents and my ID. But after 12hrs, X support helped me recover the account, I changed the password, enabled all 2FA options (eventhough I did it from the beginning but hacker bypassed it), and they told me they revoked all sessions. Since then, I’ve only been logging in from the official mobile app and all other staff only got delegated, not login access.<p>Second time, 2 weeks later (yesterday)— I suddenly get kicked out of the app, all my team delegator members lose access too, and when I try to log back in, it says it can’t find my email. . But this time, I never got any notification from X saying the email was changed like the first time.<p>My email is totally secure — no sign of compromise, no new login sessions.<p>SIM is fine. No new logins. I didn’t click on anything sketchy nor install any apps recently since that first phishing attack.<p>I’m wondering:<p>1. Can someone change the email on an X account without triggering a notification to the original email?<p>2. Does X suppress those if someone contacts support and claims the original email is compromised after 2 weeks?<p>Would love to hear if anyone else has seen something like this or knows how the backend systems work. I&#x27;m still waiting on X support, but this is really bothering me.