Account hijacked despite 2FA: victim urges passkeys, as teortaxesTex pitches always-on agents for email alerting

teortaxesTex · x · 2026-10-08

@sheriyuo's X account was taken over on Oct 1 despite 2FA being enabled, one day after a suspicious-login email he ignored. His Gmail stayed under his control and he never entered credentials on any phishing site, suggesting the attacker only had his password yet somehow bypassed 2FA. He advises unique strong passwords per account and passkeys over 2FA alone.

teortaxesTex draws a product lesson from it: one of the highest-utility uses of always-on agents would be alerting him when something truly important lands in email, since avoidance habits around DMs and inbox regularly burn him.

Original post →

More from Safety

Safety channel →