Static

BT Email users hit by barrage of unsolicited password reset PINs

First reported by The Register ·

The signal ●○○○ Compiled by AI from The Register, the single source so far
Why you might care

Your BT email password reset messages are being sent without your request, and you should ignore them.

What happened

BT Email users are experiencing a flood of unsolicited password reset PINs, with some reporting hundreds or even over a thousand messages within short periods. Customers began noticing the surge of PIN texts and emails over the weekend, prompting BT to acknowledge the issue and launch an investigation. The telco has stated that accounts remain secure and that affected customers do not need to take immediate action beyond ignoring the messages and remaining vigilant. However, at least one user claims to have lost access to their email and BT ID during the barrage, suggesting a potential, though unconfirmed, account compromise linked to the incident. The exact cause of the widespread PIN distribution is currently unknown, with possibilities ranging from external malicious attempts to internal system faults. BT is reportedly looking into the matter and has been asked to provide details on the number of affected customers, the origin of the messages, and any evidence of malicious activity, as well as their rate-limiting practices for password resets.

What it means

The widespread distribution of unsolicited password reset PINs to BT Email users points to a potential vulnerability or a large-scale attack targeting the telco's recovery mechanisms. This incident raises questions about the robustness of BT's security protocols, particularly its rate-limiting and validation processes for password resets, especially if malicious actors are indeed behind the barrage. It also highlights the growing sophistication of attacks that can inundate users and support systems, even if the core accounts remain secure.

While BT asserts account security, the report of a lost account during the PIN flood warrants close monitoring for any further evidence of unauthorized access or data breaches. The situation could signal a new tactic in account takeover attempts, where overwhelming users with legitimate-looking recovery messages distracts from or facilitates a more direct compromise. The market will be watching BT's investigation closely to understand the root cause and the subsequent security enhancements implemented to prevent recurrence.

AI-written summary. May contain errors.

Email