DEV Community

ahmed isam
ahmed isam

Posted on Originally published at digital-footprint-health.shop

An X Email Change Alert You Did Not Cause: The First Five Minutes and the Checks After

--
title: "An X Email Change Alert You Did Not Cause: The First Five Minutes and the Checks After"
description: "An email change notification means either you made the change or someone with working login access did. This covers how to tell the two apart, the five steps that narrow an attacker window fastest, and the checks worth running once the change has been reverted."
tags: ["security", "privacy", "twitter", "howto"]

canonical_url: https://digital-footprint-health.shop/blog/x-email-change-security-alert

Email change notifications are easy to wave off. Most people scan the subject line, confirm it was not them, and close the tab. When it really was not you, the implication is worse than a wrong notification. Someone already holds working login access and is replacing your recovery route with their own.

The usual sequence runs: change the email, then the password, then revoke your other sessions. In the first few minutes after the alert, the order of actions matters more than the number of them.

Separate the three cases first

Case How to tell What to do
You made the change Timing and content match your own activity Nothing. Close the notification
You did not Wrong time, no such action from you Work through the five steps
Looks like a notice but reads oddly Wrong link domain, asks for your password Do not click. Open the official app and verify directly

The third row is the standard phishing shape. A real notification does not ask you to enter your password inside an email. The test is simple: skip the link, open the app yourself or type the domain by hand, and read the account settings.

The five steps, in order

The sequence is deliberate. Followed in order it narrows the attacker's window as much as possible.

  • Click nothing in the email. Open the official app where you are already signed in, or type the domain manually, then check which address is currently bound to the account.
  • Change the password now. A brand new password that has never been used anywhere else. Change the mailbox password too, since the inbox is usually the entry point for recovery.
  • Turn on or reset two-factor authentication. A validator app or a hardware key is the better choice. SMS codes are exposed to SIM swap attacks, where a number is ported to a card the attacker controls.
  • Revoke other sessions. Sign every device out except the one in your hand. Then review connected app authorisations and remove anything whose purpose you cannot explain.
  • Check and restore the email. If the address was changed to something unfamiliar, set it back to one you control. Then confirm two-factor authentication survived the change.

If the account is already inaccessible at step one, account recovery comes first, and the evidence you will need is the registration date, historical email addresses and usual login devices.

Checks to run after you have reverted it

Kicking the other party out stops the bleeding. While they held access they may have done other things, so go back and verify.

  • Login history. Look for devices, locations or time windows you do not recognise and work out the footprint.
  • Published activity. New posts, direct messages or follows. Direct messages matter most, because they are the usual route for running a scam against your contacts.
  • Linked accounts. Anything else registered with the same email, financial and email services especially, for abnormal sign-ins.
  • Forwarding rules and filters. Auto-forwarding is a quiet persistence method and gets missed constantly. An attacker who cannot stay logged in will often leave a rule that copies mail to an address they control.

The set takes about fifteen minutes. The forwarding rule is the one most likely to be left behind.

How an email change gets triggered at all

It requires a live session, a working password, or a recovery path through the mailbox. That is why changing the mailbox password belongs in the same pass rather than afterwards. Leaving the inbox untouched leaves the recovery route open, and the recovery route is what the attacker used.

Telling a real notice from a fake

Two checks settle it. First, the link domain: a legitimate notice points at a domain you recognise, and hovering rather than clicking shows the destination. Second, the ask: no legitimate notification asks for your password inside the email body.

If the notice passes both checks and the change was not yours, treat it as a real compromise and work the five steps. If it fails either, report it as phishing and do not interact with the message at all.

Reducing the odds over time

Two habits cover most of it. Keep a valid two-factor method on the account and on the mailbox, and review connected app authorisations a couple of times a year. Authorisation lists grow silently, and an app granted access three years ago for a purpose nobody remembers is exactly the kind of route that gets reused.

Top comments (0)