I received a notification last night that someone changed my shipping address on Macys.com and when I visited the website, there was an open order for a PS5 with delivery to:

DONT IEPN 203 W PITTSBURGH AVE WILDWOOD CREST NJ 08260

After logging into Macy’s I got 43 emails at once to seven different services like “Excalidraw” and “Sportograf” trying to login using a magic link.

At this point was was pretty nervous so I checked my main email security. Sure enough, there have been repeated login attempts under my account going on every few minutes for weeks.

I also saw there was an attempted login to my cellphone or home internet company.

I use 2FA, authenticators, etc. Basically what else should I be doing? Is there any way to be more preventative? I really don’t wanna chuck this email but it is possible that may be the safest recourse. I do use this email for almost 300 different accounts to various things though.

  • You can change your password to be sure, but there’s nothing you can do to prevent the attacker from entering your email address into the login field of your mail service.

    Be extra watchful for phishing attempts. If you’re using TOTP or SMS for authentication, consider using Passkeys or a Yubikey(-like device), as TOTP and SMS codes are easily phished.

    Changing your password on your Macy’s account and any other account that may share a password should be a priority, if you haven’t already. Other than that, not much you can do but hope the annoyance goes over quickly.

    • LazaroFilm@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      29 days ago

      If you don’t use Macys, consider deleting your account there or changing your email connected to it.