Phishing… and yahoo mail

Author
Discussion

Austin_Metro

Original Poster:

1,388 posts

63 months

Friday 2nd May
quotequote all
Hello tech gurus,

My dear old mum verified her email address in response to a simple phishing request. And gave PW.

A few days later, they took over her email and sent all her contacts a request to help her with something on Amazon (presumably if anyone replies, this will be a request for e vouchers)

We reset the password and got back in. I’ve emailed all to say it’s a fraud.

The email account was set so all replies went to the delete box (a filter) so if you did get back in, you wouldn’t see the replies before the fraudster did.

The email is an old sky one, run through yahoo.

The recent account activity mentions an “app password was added” this was by the fraudsters. I don’t understand what that is or how to disable it but I have “signed out of all devices” and set a new password - which works on the web and on the iPad app.

Anymore I should do please?


Edited by Austin_Metro on Friday 2nd May 13:01

Keypad

93 posts

63 months

Friday 2nd May
quotequote all
I think the best course of action would be to export the contact list (if possible - else make a manual list); close / delete the account (again, if possible); and set her up with a web-based email such as Gmail or proton mail; then import or manually create the contacts.
I'd avoid an Outlook account as it seems to be getting infested with adverts these days.

egomeister

7,177 posts

278 months

Friday 2nd May
quotequote all
An app password is one setup specifically for a particular app and is considered a more secure way of accessing your account through an app.

Yahoo can be a bit messy when it comes to security settings, but if you log into yahoo mail on the web, then click on your username on the top right, then account info, then security, you should then be able to see app passwords on the right under the "how you sign into yahoo" section. Click on manage app passwords and you should be able to delete.

Austin_Metro

Original Poster:

1,388 posts

63 months

Friday 2nd May
quotequote all
Keypad, Why do you recommend that? Because we’ll never be sure they don’t have access?

Austin_Metro

Original Poster:

1,388 posts

63 months

Friday 2nd May
quotequote all
egomeister said:
An app password is one setup specifically for a particular app and is considered a more secure way of accessing your account through an app.

Yahoo can be a bit messy when it comes to security settings, but if you log into yahoo mail on the web, then click on your username on the top right, then account info, then security, you should then be able to see app passwords on the right under the "how you sign into yahoo" section. Click on manage app passwords and you should be able to delete.
Thanks ego.

Under “this is how you sign in now” I don’t have any reference to an app passcode.

It’s either “password” and it was changed when I changed it. Or “passkeys” and it offers that I can “create passkey”

There’s an option further up to “enable 2 step verification “ but if I click on that nothing happens.

bitchstewie

58,622 posts

225 months

Friday 2nd May
quotequote all
If you haven't already done so check with your mum if she uses that password for other services and if she does change it asap with those too.

If she uses it everywhere focus on the important stuff i.e. Amazon or anywhere someone could login and start buying/doing stuff.

And enable 2FA on the Yahoo account and better still drop it and get a Gmail account or similar smile

egomeister

7,177 posts

278 months

Friday 2nd May
quotequote all
Austin_Metro said:
egomeister said:
An app password is one setup specifically for a particular app and is considered a more secure way of accessing your account through an app.

Yahoo can be a bit messy when it comes to security settings, but if you log into yahoo mail on the web, then click on your username on the top right, then account info, then security, you should then be able to see app passwords on the right under the "how you sign into yahoo" section. Click on manage app passwords and you should be able to delete.
Thanks ego.

Under “this is how you sign in now” I don’t have any reference to an app passcode.

It’s either “password” and it was changed when I changed it. Or “passkeys” and it offers that I can “create passkey”

There’s an option further up to “enable 2 step verification “ but if I click on that nothing happens.
Nothing to the right or below where it says passkeys?




If an app passwords exists, it should say "generate or manage app passwords" or similar.


Yahoo mail is pretty horrible, so I agree with the other post above to move away to something like gmail if possible. To get the instructions above it took me half a dozen attempts to get a verification code to allow me to login!

Austin_Metro

Original Poster:

1,388 posts

63 months

Friday 2nd May
quotequote all
bhstewie said:
If you haven't already done so check with your mum if she uses that password for other services and if she does change it asap with those too.

If she uses it everywhere focus on the important stuff i.e. Amazon or anywhere someone could login and start buying/doing stuff.

And enable 2FA on the Yahoo account and better still drop it and get a Gmail account or similar smile
Thanks Stewie - I have asked on passwords. She seems to use unique ones - it’s surprising she could tell the phisherman what it actually was.

Austin_Metro

Original Poster:

1,388 posts

63 months

Friday 2nd May
quotequote all
This is all that comes up.


egomeister

7,177 posts

278 months

Friday 2nd May
quotequote all
Not sure then! That's the same place I'm looking but your pages is slightly different.

If you go to the next tab, recent activity, you might be able to see where the account is currently logged in and do something from there

Austin_Metro

Original Poster:

1,388 posts

63 months

Friday 2nd May
quotequote all
egomeister said:
Not sure then! That's the same place I'm looking but your pages is slightly different.

If you go to the next tab, recent activity, you might be able to see where the account is currently logged in and do something from there
Thanks!

I have tried looking at all the tabs. I’ve also done the “secure your account” option which disconnected all others but the webmail portal I was going through. Might that have disabled the app password?

egomeister

7,177 posts

278 months

Friday 2nd May
quotequote all
Possibly, yeah. If the only current login in the recent activity is your current one then you are probably ok. Anything using the app password should be fairly identifiable on that page I think

bad company

20,495 posts

281 months

Friday 2nd May
quotequote all
egomeister said:
Nothing to the right or below where it says passkeys?




If an app passwords exists, it should say "generate or manage app passwords" or similar.


Yahoo mail is pretty horrible, so I agree with the other post above to move away to something like gmail if possible. To get the instructions above it took me half a dozen attempts to get a verification code to allow me to login!
What’s wrong with Yahoo Mail? I’ve used it for years, changing everything would be a pain.

egomeister

7,177 posts

278 months

Friday 2nd May
quotequote all
bad company said:
egomeister said:
Nothing to the right or below where it says passkeys?




If an app passwords exists, it should say "generate or manage app passwords" or similar.


Yahoo mail is pretty horrible, so I agree with the other post above to move away to something like gmail if possible. To get the instructions above it took me half a dozen attempts to get a verification code to allow me to login!
What’s wrong with Yahoo Mail? I’ve used it for years, changing everything would be a pain.
I find its quite unreliable. Not so much the email itself, but everything around it like login authentication etc. For example, I've still not received verification codes by SMS or whatsapp that I requested earlier today - the only way I got in was by having a backup email it could send a code to. I tried added 2 factor with an authentication app, but on the first attempt it didn't accept the codes generated... first site I've had that issue with.

Spam filtering is also not up to the level of gmail for example.

There's not any fundamental flaw that would mean I'd want to switch at all costs, but if it were me I'd be transitioning stuff away from it when convenient. One thing I would say for sure is have lots of ways for backup verification as I could have easily been locked out today despite giving the correct password and having the correct phone no linked.

Austin_Metro

Original Poster:

1,388 posts

63 months

Saturday 3rd May
quotequote all
Thanks all.

Mercdriver

3,000 posts

48 months

Saturday 3rd May
quotequote all
Similar problems too, keeps crashing and having to log in again through sky website. Also get unwanted ads despite call blocker

Reluctant to change e mail address as I had it for years and up to now it has suited me but recently it is a PITA.

Is there any point in complaining to sky?

bitchstewie

58,622 posts

225 months

Saturday 3rd May
quotequote all
Realistically what do you think Sky are going to do?

Honestly I wouldn't look beyond Gmail.

It just works.