Account Recovery Security
Spot a hijacked password reset before you type anything.
What Is Account Recovery Security?
A password reset flow exists to hand an account to someone who cannot log in, which is exactly what makes it worth attacking. You'll see a fake suspension warning lead to a page that asks for the current password, then watch the notifications arrive: password changed, recovery email changed, security questions changed. You'll re-read the original message and name what was missed, check where the link really pointed, call IT on a number of your own, and file the report.
What You'll Learn in Account Recovery Security
- Identify the warning signs of a spoofed password reset email, including manufactured urgency and account-suspension threats
- Recognize that a legitimate reset flow never asks for your current password, and treat that request as the attack itself
- Inspect where a reset link actually resolves before entering any credential on the page it opens
- Respond to a confirmed account takeover by contacting IT Security through a number you already trust, not one supplied in the message
- File an incident report that captures the spoofed sender, the phishing URL and the credentials entered so the security team can contain the damage
Account Recovery Security — Training Steps
-
A Busy Monday Morning
It's Monday morning and you have a full day of patient consultations ahead. You sit down at your home office desk and prepare to log into the patient management system.
-
The Unexpected Password Reset
Before you can even open your browser, a notification pops up on your desktop. A new email has arrived - a password reset request for your work account. Strange. You didn't request a password reset. But lately IT has been rolling out new security policies, so perhaps this is part of that.
-
The Pressure to Act
The email looks official. The logo seems right, and the message is urgent - account suspension would mean you couldn't access patient records all day. You need to reset your password quickly before your first patient consultation. There's no time to investigate.
-
Entering Current Credentials
The password reset page loads. It asks for your current password to verify your identity before allowing you to set a new one. This seems like a reasonable security measure - after all, anyone could click a reset link.
-
The Error Message
After submitting, the page displays an error: 'Unable to process request. Please try again later or contact IT Support.' Frustrated, Alice closes the browser and decides to try the regular login page instead. At least she knows her old password still works.
-
A Troubling Discovery
Twenty minutes later, Alice receives a flood of email notifications. Password changed. Recovery email updated. Security questions modified. She tries to log in with her old password. Access denied. She tries the new password she just set. Also denied. Her account has been completely taken over.
-
Realizing the Attack
Alice's heart sinks. The email from IT Security confirms her worst fears - her account has been completely compromised. The password, recovery email, and security questions were all changed by someone else.
-
Analyzing the Phishing Email
Now Alice looks back at the original password reset email with fresh eyes. What warning signs did she miss?
-
Checking the Link
The email contained a link to reset the password. Let's examine where that link actually leads.
-
Contacting IT Security
Alice needs to act fast. She picks up her phone to call IT Security using the number from her contacts - not any number from the suspicious emails.
Security Framework Coverage
MITRE ATT&CK
- T1098.005 Account Manipulation: Device Registration
- T1556 Modify Authentication Process
CIS Controls
- CIS 5 Account Management
- CIS 14.3 Train Workforce Members on Authentication Best Practices
NIST CSF
- PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
- PR.AA Identity Management, Authentication, and Access Control