I was a very happy FastMail customer until a hacker asked them to reset my password. After _incorrectly_ answering a handful of questions asked by the FastMail support, the recovery email address was changed and a password reset link sent. From there, the hacker attempted password resets on other services. Initially, FastMail was dismissive that this was a simple "mix-up" and didn't disable access to the hacker for 7…
Good morning. I'm going to be here to answer specific questions, and I owe you a personal response to this as well, which I'm about to start working on! There is no doubt that in this specific case our human factor screwed up, and I'm really sorry about that. First I'm going to post the standard response that our team has written for any new support tickets that come in about this today, then write my own personal ap…
How many of those employees are there?
In what fashion do you audit and track the activities of those employees?
What training are these employees given to avoid social engineering? What firm provides the courseware?
What's the escalation process for complicated, non-no-brainer reset situations? If a support person isn't absolutely sure whether they should reset something, how do they get a second opinion?
Are the support people who are entitled and able to make these changes incentivized to close tickets as quickly as possible?
Do you monitor "out-of-process" changes to recovery email and password settings, so that you can see trends over time and by particular staff members?
Has any third party security firm assessed your service recently specifically for this attack vector, for instance by conducting social engineering testing against your support staff? What's the firm?
How are you MINIMIZING, rather than just improving, the "human factors" involved in assessing whether accounts can be altered based on anonymous incoming callers and requesters?
This is a HUGE, TERRIFYING vulnerability. Email providers are the single most important security service people use; if your email is compromised, many (most!) of your other services are compromised as well.