Locked user has requested we change their obsolete email address. Possible security risk?

  • Thread starter Thread starter Mr Lucky
  • Start date Start date
M

Mr Lucky

Guest
We have received a request via contact form from a user whose account is set to locked. It seems the email address registered is no longer valid and they are requesting the password reset be sent to a new email address. Although this could be totally legit I am concerned that this could also be someone attempting to take over an old account.

What is the best course of action in this case?

Perhaps grant the request to change email but set the account to awaiting approval?

Or Remove the...

Read more

Continue reading...
 
Back
Top