Someone is trying to steal my domain
Someone is trying to steal my domain. He almost made it through the chat support.
Firts of all: I have two-factor protection in my account and in my mail. I have checked viruses (nothing), I use iPhone.
1. Some person contacted with CHAT without loggin into the account
2. He told the chat manager my name and domain name (oppened info)
3. Chat manager asked pin code from the account to verify identity
4. He told them he can not log in and he can't remember pin
=> So, he gave to support nothing. No documents, nothings.
6. Chat manager answered: "Sure. I have sent the one-time verification code to your primary email address. Please check and provide the verification code to authenticate your account."
7. The scammer answered: "sure"
8. Then the scammer somehow gives support CORRECT CODE (HOW?!)
9. Chat manager: "Thank you. I will unlock your domain and request the auth code for you."
THEY HAVE ENOUGH A CODE FROM THE MAIL FROM A UNSIGNED PERSON WITHOUT A PIN AND A PASSED TWO-FACTOR PROTECTION TO INITIATE A DOMAIN TRANSFER!!!!!!
The same time I was attacked with email spam, scammer tryed to hide his actions. But I noticed and contacted with the support.
I still don't understand where he got the code to verify the identity. Because I have two-factor protection in my mail. But I see that The presence of two-factor account protection can not save me. Because the kind chat manager sent everything to the mail and initiated the transfer instantly (if you make a request through your account, you have to wait 3 days).
MOREOVER I checked my mail logs. There are only inputs from my IP and from my devices (PC and iPhone). It's all me. That is, the scammer did not have access to my mail and could not take the code there. And further. If he had access to the mail, he would simply restore the account.
Ant way... Zero security. Two-factor protection does not work. Everything can be bypassed by simply writing to the chat.
31 July 2023
Unprompted review