This week scammers tried to do an account takeover on my Chase account.

  • This week scammers tried to do an account takeover on my Chase account.
    • They succeeded in convincing Chase to change the email address on file (!!) but I noticed minutes later and was able to recover my account.
    • They did a technique you might call "email bombing" or "notification flooding."
    • As soon as they convinced the phone support to change my email address (despite having only my credit card number and public information about me), they initiated a flood of emails to my email address.
    • I got hundreds of emails from random sites around the world about me signing up for an account, or to verify my email.
    • These are all real services, so Gmail marked them as priority and not spam.
    • But it was like a smokescreen, obscuring the one account email that was real and very important.
    • Thank goodness I noticed it within minutes![gg]