I received a notification last night that someone changed my shipping address on Macys.com and when I visited the website, there was an open order for a PS5 with delivery to a NJ address.

After logging into Macy’s I got 43 emails at once to seven different services like “Excalidraw” and “Sportograf” trying to login using a magic link.

At this point was was pretty nervous so I checked my main email security. Sure enough, there have been repeated login attempts under my account going on every few minutes for weeks.

I also saw there was an attempted login to my cellphone or home internet company.

I use 2FA, authenticators, etc. Basically what else should I be doing? Is there any way to be more preventative? I really don’t wanna chuck this email but it is possible that may be the safest recourse. I do use this email for almost 300 different accounts to various things though.

  • SavvyWolf@pawb.social
    link
    fedilink
    English
    arrow-up
    23
    ·
    2 months ago

    You’re assuming that the attacker is using their own IP rather than a compromised system owned by someone else.

    Likewise, they might be using someone else’s address with the intent to steal a package from their porch or something.

    It’d be rather silly for a theif to use their own details.