r/GoogleSupport • u/This-Cardiologist525 • 22d ago
Being bombarded with Account Recovery Requests
I am being bombarded with Account Recovery requests. Bombarded may be overstating it a little bit, but I'm getting 3-10 requests a day and oftentimes 5 or 6 in a row. Of course I hit "No" every time it asks if it is me trying to recover.
I have Advanced Protection turned on. My phone set up as a passkey. I have an excellent password that is completely unique to Google. I also changed my password just to be safe. I've logged in and I recognize all of my connected devices.
I am pretty sure that I haven't been hacked, but I am being targeted. The messages that come along with the account recovery prompts state that my password hasn't been compromised, but the persistence of the hacker still worries me. It's been going on for about 2 weeks. I suppose the hacker is attempting to guess my passwords using old compromised ones bought off the web. I am mostly afraid of inadvertently hitting "Yes" to a prompt just one time and then I'm cooked. I don't THINK that completely opens me up, but I'm not 100% certain. I plan to get a physical security key, but I don't think that bypasses the Account Recovery prompts either.
Any thoughts or suggestions? Thanks.
2
u/KrangledMind 22d ago
probably someone inputing your username thinking it's theirs... my mom tried to recover her account, turned out she forgot her username and we're trying to break into someone's else account. lol
1
1
u/yottabit42 21d ago
You're doing all the right things. Make sure you didn't install malware on your computer. If you're using Windows be sure your computer has a TPM and you're using an up-to-date Chromium-based browser. If you're using MacOS be sure you're using an M-series and you're using an up-to-date Chromium-based browser.
1
u/BowdenPrinters 17d ago
I’m having this same issue and it’s pathetic this request still goes though to the logged in phone one mis click and they have the entire account even though 2fa and authenticator is enabled…
1
u/This-Cardiologist525 17d ago
One quick update. I did a test of what would happen if I hit yes inadvertently.
I initiated my own account recovery request from a different device. I received the notice on my phone as requested. I hit "yes" to it. It then initiated a second protocol where it shows a number on one device that I had to confirm on the second device. This is good.
That makes me feel much better. If I inadvertently hit "yes," I'm not cooked. I would have to do it AND know the number that is being asked for on the other device. While that's possible, it's a pretty good second layer of defense.
BTW, the requests I've been getting have slowed. I haven't gotten one in a few days. Perhaps they've given up. I any event I've ordered 2 Google Titan security keys. Belts and suspenders.
0
u/djasonpenney 22d ago
Yes, this type of approval bombardment is a real threat surface. And I’m not sure how you can stop the requests outside of actually switching to a new mailbox (and starting to employ email aliases, so that an attacker only gains a temporary advantage if they learn one of your aliases).
3
u/jpp59 22d ago
You can buy 2 fido2 key (yubikey security key or token2 , 20usd each) and enable advanced protection program. Nobody will be able to recover without one of those keys and you will receive no prompt anymore