TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Nike.com allows easy account take over

16 pointsby sem000almost 3 years ago
I am unsure whether to post this as it exposes potential harm to millions of accounts...<p>Nike.com apparently lets you take over an account by calling in and verifying the email address and phone number associated with the account.<p>My account was just hacked, someone called in and used my information to change the email address to my name @outlook.com (same as my gmail account).<p>Their only solution was to delete my account. This is terrifying.

4 comments

sc00tyalmost 3 years ago
Someone did this with my Ebay account. They changed the phone number, email (same email, except it was @outlook.com), and password. Thankfully, Ebay has an account takeover department that helped me fix the issue within an hour.<p>For fun, I ended up emailing that @outlook.com email asking them why&#x2F;how they did it and they just replied back &quot;why can&#x27;t you just let go of it...&quot;.
bploetzalmost 3 years ago
<a href="https:&#x2F;&#x2F;www.nike.com&#x2F;help&#x2F;a&#x2F;responsible-disclosure" rel="nofollow">https:&#x2F;&#x2F;www.nike.com&#x2F;help&#x2F;a&#x2F;responsible-disclosure</a>
评论 #32154480 未加载
nutbearalmost 3 years ago
Thanks for sharing your story!<p>A decent amount of disclosure programs explicitly call out social engineering as unacceptable conduct and submissions.<p>However, social engineering is a very valid method for attackers and in many cases, offers the path of least resistance.<p>While I understand why companies don’t want good faith security research to call and try to trick the human factor, this is still a very real attack vector that needs attention and to be fixed as in what you’ve described.
fronalmost 3 years ago
Can&#x27;t you just call in and change it back then?
评论 #32156654 未加载