• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Account Recovery Backdoor

Also known as: Account Manipulation

PERSISTENCEMITRE ATT&CK: T1098 Account Manipulation: describes adversary actions that modify account settings for persistence, including modifying credentials and permission groups

After compromising a victim's online account, attackers modify the account recovery settings -- such as the recovery email address, recovery phone number, and security questions -- to attacker-controlled values. This ensures the attacker can regain access through password reset flows even if the vic…

Common attack flows

How it fits in a scam

This technique shows up duringPERSISTENCE

Before

  • Account TakeoverEXPLOITATION

After

  • Fund SiphoningMONETIZATION
  • Identity TheftEXPLOITATION

Defense

How to defend against this

How to spot it

  • Notification or email from your service provider that your recovery phone number or email address has been updated without your action
  • Unable to use 'forgot password' flow because the recovery options no longer point to your phone or email
  • Receiving a verification code you did not request
  • sent to your old recovery info (platforms like Google send codes to previous recovery info for 7 days after a change)
  • Login alerts from unfamiliar devices or locations appearing in your account security activity log
  • Locked out of your account entirely after a password reset you did not initiate
  • Security questions no longer accept answers you previously set
  • Unfamiliar recovery email or phone number visible in your account security settings

Tools you can use

  • Multi-Factor AuthenticationCost low · Effect high
  • Hardware Security KeysCost medium · Effect high
  • Use Authenticator AppsCost low · Effect high

Further reading

  • Doppel

    Explains how attackers change email, phone, password, and MFA settings post-compromise to prevent victim recovery, describing the persistence phase of ATO

  • Vectra AI

    Describes how attackers establish persistence by modifying account recovery settings after account takeover, noting that recovery workflows must verify identity without relying on compromised methods

  • Mailbird

    Details how email recovery options become privacy backdoors, including SIM swap attacks to hijack recovery phone numbers (citing $38M T-Mobile case) and password reset poisoning

  • Identity Guard

    Describes how recovery phone/email changes are a primary indicator of Google account compromise: 'Hackers may change your account recovery information to prevent you from regaining access or proving your identity to Google'

  • Google Workspace Help

    Google's official guide on identifying and securing compromised accounts, including reviewing recovery addresses, revoking OAuth tokens, and enrolling in 2-step verification

  • FBI IC3

    FBI Public Service Announcement on ATO fraud noting that criminals change account passwords to lock owners out; over 5,100 complaints totaling $262M in losses since January 2025

  • MITRE ATT&CK

    T1098 Account Manipulation: describes adversary actions that modify account settings for persistence, including modifying credentials and permission groups

Related techniques

Variants

  • Cloud Account Persistence

Same stage

  • Remote Access Tool
  • Email Forwarding Persistence
  • Payment Method Injection
  • MFA Device Registration
  • Stalkerware
  • +2 more

Similar defense

  • SIM Swap
  • Data Breach Harvesting
  • Man In The Middle
  • Account Takeover
  • Credential Theft
  • +5 more