Technique
Account Recovery Backdoor
Also known as: Account Manipulation
After compromising a victim's online account, attackers modify the account recovery settings -- such as the recovery email address, recovery phone number, and security questions -- to attacker-controlled values. This ensures the attacker can regain access through password reset flows even if the vic…
Common attack flows
How it fits in a scam
Defense
How to defend against this
How to spot it
- Notification or email from your service provider that your recovery phone number or email address has been updated without your action
- Unable to use 'forgot password' flow because the recovery options no longer point to your phone or email
- Receiving a verification code you did not request
- sent to your old recovery info (platforms like Google send codes to previous recovery info for 7 days after a change)
- Login alerts from unfamiliar devices or locations appearing in your account security activity log
- Locked out of your account entirely after a password reset you did not initiate
- Security questions no longer accept answers you previously set
- Unfamiliar recovery email or phone number visible in your account security settings
Further reading
Doppel
Explains how attackers change email, phone, password, and MFA settings post-compromise to prevent victim recovery, describing the persistence phase of ATO
Vectra AI
Describes how attackers establish persistence by modifying account recovery settings after account takeover, noting that recovery workflows must verify identity without relying on compromised methods
Mailbird
Details how email recovery options become privacy backdoors, including SIM swap attacks to hijack recovery phone numbers (citing $38M T-Mobile case) and password reset poisoning
Identity Guard
Describes how recovery phone/email changes are a primary indicator of Google account compromise: 'Hackers may change your account recovery information to prevent you from regaining access or proving your identity to Google'
Google Workspace Help
Google's official guide on identifying and securing compromised accounts, including reviewing recovery addresses, revoking OAuth tokens, and enrolling in 2-step verification
FBI IC3
FBI Public Service Announcement on ATO fraud noting that criminals change account passwords to lock owners out; over 5,100 complaints totaling $262M in losses since January 2025
MITRE ATT&CK
T1098 Account Manipulation: describes adversary actions that modify account settings for persistence, including modifying credentials and permission groups