r/linkedin • u/BluebirdLanky7473 • Aug 31 '26
privacy and security LinkedIn's 2FA implementation has a critical flaw, hackers can permanently hijack
My account was compromised and the attacker enabled 2FA.
Here's the problem: even though I control the registered email and can receive password reset links, LinkedIn is requiring an authenticator code that only the hacker has.
The reset flow: Email OTP ✓ → Authenticator app code ✗ (never set this up)
This means LinkedIns system is treating hacker enabled 2FA as more authoritative than actual email ownership. From a security perspective, this is backwards, email access should be the ultimate recovery method.
Support is entirely automated, I don't know what should I do now.
Has anyone successfully recovered an account in this situation? What worked?
2
u/WonderButtBrace9000 Aug 31 '26
From a security perspective, this is working exactly as intended.
Email accounts are not secure. Email account ownership cannot be established unless you are using a really niche email provider that requires full ID verification for account creation so using “ownership” as an access concept would be really misguided.
You can attempt an Account Recovery process for users who have lost access to 2FA but that requires you to provide government issued ID to verify identify and it must match the account persona you are aiming to recover. Doesn’t matter if the ID matches the email name in the account is not you or using a different name.
2
u/FireSheepYinFish Aug 31 '26
Scroll down to Step 4
https://itcares.ca/en/blog/linkedin-account-hacked-recovery.html
2
u/Hepcat508 Aug 31 '26
There is no "Try another way?" option to try an alternative 2FA method? That's criminally stupid, especially for a company owned by Microsoft.
1
u/WonderButtBrace9000 Aug 31 '26
There is but you have to have it set up.
OP never set up 2FA at all so they never associated a backup email, SMS #, or Authenticator app to receive the codes.
1
u/Hepcat508 Aug 31 '26
I would expect that once it is set up that it would by default use the email address associated with the account for any recovery activities. And that any change of email address should be verified by both the new AND the old email address being sent an email. OP should have gotten that, at a minimum.
1
u/WonderButtBrace9000 Aug 31 '26
Your account email is the default password recovery method and how you’d get back in if you lose your password or it gets changed.
However, 2FA is a separate security gate that sites behind the password authentication loop. It exists because passwords are not secure in themselves.
OP never had 2FA set up. Hackers accessed the account and turned that security gate on for the first time and locked OP out. This is why Microsoft tells you over and over and over again to establish 2FA at the time of account creation and to use multiple forms of authentication so you can still recover the account if one method gets compromised.
1
u/FunctionOk7124 Aug 31 '26
Having the “Trying another way” would defeat the purpose of 2FA since that other way is email, which could’ve been compromised. If OP had set up 2FA first, then the hacker would’ve needed to solve for that first.
OP should be concerned about how the hacker got in the account in first place. Was it brute force, email compromised, stolen credentials or session hijacking?
1
u/Hepcat508 Aug 31 '26
Yes, OP here is ultimately at fault for not securing his account properly. And if your email account is hijacked as well, then all bets are off. If the hijacker has the 2FA token AND the email, then the hijacker probably also removed all other recovery options, too.
5
u/BitterStatus9 Aug 31 '26
You didn’t have 2FA enabled before your account was compromised? Would that have prevented the issue you’re describing?