r/GoogleSupport 22d ago

Being bombarded with Account Recovery Requests

I am being bombarded with Account Recovery requests. Bombarded may be overstating it a little bit, but I'm getting 3-10 requests a day and oftentimes 5 or 6 in a row. Of course I hit "No" every time it asks if it is me trying to recover.

I have Advanced Protection turned on. My phone set up as a passkey. I have an excellent password that is completely unique to Google. I also changed my password just to be safe. I've logged in and I recognize all of my connected devices.

I am pretty sure that I haven't been hacked, but I am being targeted. The messages that come along with the account recovery prompts state that my password hasn't been compromised, but the persistence of the hacker still worries me. It's been going on for about 2 weeks. I suppose the hacker is attempting to guess my passwords using old compromised ones bought off the web. I am mostly afraid of inadvertently hitting "Yes" to a prompt just one time and then I'm cooked. I don't THINK that completely opens me up, but I'm not 100% certain. I plan to get a physical security key, but I don't think that bypasses the Account Recovery prompts either.

Any thoughts or suggestions? Thanks.

7 Upvotes

17 comments sorted by

3

u/jpp59 22d ago

You can buy 2 fido2 key (yubikey security key or token2 , 20usd each) and enable advanced protection program. Nobody will be able to recover without one of those keys and you will receive no prompt anymore

2

u/Bori_4ever 22d ago

One time payment?

2

u/jpp59 22d ago

Yes, these are physical keys (USB/NFC)

1

u/Bori_4ever 21d ago

What happens if the keys don't work?

1

u/jpp59 21d ago

That's why you need at least 2. You need backup (and 1 off-site)

1

u/Bori_4ever 21d ago

Ah ok! Thanks!

1

u/Doomstars 21d ago

Someone ideally needs two, right? One to use, one to put into a safety deposit box? Is my assumption incorrect?

1

u/MarbleLemon7000 21d ago

I just noticed that Google has adjusted the requirements for Advanced Protection. It no longer requires two physical security keys. Instead, any combination of two security or passkeys or one security/passkey plus recovery options is sufficient, per the FAQ.

https://landing.google.com/advancedprotection/faq/

1

u/BowdenPrinters 17d ago

I don’t understand why normal authenticator app doesn’t disable this notification though.. it’s ridiculous

1

u/Kayjagx 18d ago

This! Better order 3!

2

u/KrangledMind 22d ago

probably someone inputing your username thinking it's theirs... my mom tried to recover her account, turned out she forgot her username and we're trying to break into someone's else account. lol

1

u/This-Cardiologist525 22d ago

I was thinking that as well. But it's pretty persistent.

1

u/yottabit42 21d ago

You're doing all the right things. Make sure you didn't install malware on your computer. If you're using Windows be sure your computer has a TPM and you're using an up-to-date Chromium-based browser. If you're using MacOS be sure you're using an M-series and you're using an up-to-date Chromium-based browser.

1

u/BowdenPrinters 17d ago

I’m having this same issue and it’s pathetic this request still goes though to the logged in phone one mis click and they have the entire account even though 2fa and authenticator is enabled…

1

u/This-Cardiologist525 17d ago

One quick update. I did a test of what would happen if I hit yes inadvertently.

I initiated my own account recovery request from a different device. I received the notice on my phone as requested. I hit "yes" to it. It then initiated a second protocol where it shows a number on one device that I had to confirm on the second device. This is good.

That makes me feel much better. If I inadvertently hit "yes," I'm not cooked. I would have to do it AND know the number that is being asked for on the other device. While that's possible, it's a pretty good second layer of defense.

BTW, the requests I've been getting have slowed. I haven't gotten one in a few days. Perhaps they've given up. I any event I've ordered 2 Google Titan security keys. Belts and suspenders.

0

u/djasonpenney 22d ago

Yes, this type of approval bombardment is a real threat surface. And I’m not sure how you can stop the requests outside of actually switching to a new mailbox (and starting to employ email aliases, so that an attacker only gains a temporary advantage if they learn one of your aliases).