logo

Researchers Warn of 'Hidden Risks' in Passwordless Account Recovery

ID: 69f5a0ed-cb7c-5571-89ee-6f8bf3a8fa6b

STIX ID: report--69f5a0ed-cb7c-5571-89ee-6f8bf3a8fa6b

Feed Name: Dark Reading

Threat Score
50/100

Date Published: 2025-08-11

Date Updated: 2026-04-21

Author: Arielle Waldman

...
...

**Executive Summary:** Researchers presented findings at Black Hat demonstrating widespread weaknesses in account recovery flows across major websites — including reliance on insecure channels (email/SMS), lack of MFA during recovery, inconsistent verification, active parallel sessions, and the ability for attackers to change recovery methods — which collectively enable account takeover and lockout attacks; they recommend two-factor recovery options, stricter session and device verification policies, and improved support procedures to mitigate social-engineering risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.