Apple ID being Reset - Your Apple Account password has been reset

Soldato
Joined
28 Oct 2002
Posts
3,249
Location
Essex
Hi all,

Apple iPhone 12 Pro, Family plan with 5 other members. Subscribe to 2TB.

- 2FA on
- 1 Recovery e-mail address, this e-mail is on 2FA and just checked - not been compromised.
- Password is complex, over 12 and used on nothing else.

I'm a little concerned. Around 10 minutes ago I had an e-mail pop up at home - "Your Apple Account password has been reset" It's legit as confirmed by the Apple Engineer.

I straight away reset the password
Whilst doing this, It looked like my number was being "Deactivated" using an e-sim. Only glanced quickly at this.

Received another e-mail "Your Apple Account information has been updated" Inside the body of the e-mail was "Password" again legit e-mail.

All backup and running and signed all other browsers/sessions out. On the phone with Apple now.

How is this being done? Anything I can do to prevent it? Even with the password, it should be prompting me for 2FA? I had the same thing 6 months back, assumed it may of been a password that I'd used previously on another side, looked at securing everything down.

Any help would be appreciated.
 
Last edited:
Just come off the phone to Apple, they said the first e-mail was legit and it appears that someone has tried to recover my account, unsure how they got that far?! Spoke with o2 and explained the situation - there is no other sim cards / e-sims connected to the account.

They have suggested that I create a Recovery key - therefore this is needed each time an Account Recovery is requested.
 
I didn't have any phone calls or anything - so signins from other locations etc. Just straight reset.
 
Was the email saying it was reset or that someone was trying to reset? Do you have a screenshot? I'm just curious for myself more than anything.

Also do you have any unknown devices listed as authorised on https://account.apple.com/account/manage/section/devices

If someone somehow happens to have got their device added to your account as an authorised device, they could reset the password direct from said device using nothng more than a face ID/touch ID/passcode.
 
Back
Top Bottom