Skip to primary content
Skip to secondary content

Triple-S Computers Blog – Louisville, KY computer repair specialist

Tips from the trenches of advanced computer repair

Triple-S Computers Blog – Louisville, KY computer repair specialist

Main menu

  • Triple-S Computers Home
  • Like me on Facebook!

Tag Archives: 2FA

PSA: Yahoo!/Bellsouth.net email is a target ripe for hacks recently

Posted on March 30, 2026 by Steve Schardein
Reply

I’m writing this blog post in response to a growing pattern of completely isolated account hacks of Yahoo! (and, consequently, Bellsouth.net/ATT email, which is downstream from it) that began years back, but has accelerated notably in recent months.

The common thread connecting most of these hacks is that the users do not have 2FA (two-factor authentication) switched on for the account — so it’s trivial for any attacker who happens to find the password (whether by way of a database hack, local malware/extension compromise, or mere password reuse) to just login and do their bidding.

However, worse yet, there is evidence also of script-based vulnerabilities that can force email filters to be unilaterally added to the user’s Settings without their knowledge — probably by way of a link they clicked in a targeted phishing email. These don’t even require the user to enter any information. These filters are typically used to redirect specific emails (such as those with financial institution names/terms in them) to a different folder than the Inbox (commonly “Archive”), so that the user doesn’t notice that the hacker is working to get inside those accounts and change their password/login information or steal from them.

The response to these increasingly numerous security breaches is:

  1. Change the Yahoo!/Bellsouth.net/ATT password first.
  2. Enable 2FA on the account. Verify the info.
  3. Remove any unrecognized trusted devices or login sessions from within the Yahoo!/ATT security settings.
  4. Navigate to the email settings next and inspect the filters. Remove any unrecognized filters, noting the search terms for clues as to which institutions were being targeted for account hacking.
  5. Move all affected email from the filter folder target back into Inbox and read through them.
  6. Check any affected PCs for infiltration/extension fraud.

That’s it. Similar attacks target Outlook.com email accounts, and there are some sophisticated methods hackers have been using to actually overwrite email body content in that case — forever destroying the information in exchange for (typically) some sort of ransom note. This is perhaps an even more insidious technique. However, by far, the most common email hack currently propagating is the Yahoo!/Bellsouth/ATT one. All the more reason why users ought to strongly consider transitioning off that historically troubled platform toward a stabler, more secure service such as Gmail!

Posted in Case Studies, Malware and Security | Tagged 2FA, account security, att.net, bellsouth.net, email security, hacking, phishing, yahoo email | Leave a reply

Welcome!

I'm Steve Schardein, independent technician at Triple-S Computers in Louisville, KY. This is my new repository for tips, notes, and just general thoughts about my computer repair experiences. The advice here is meant for education and reference only, and it is intended for professionals, NOT the average user. Much of it is advanced material. Just to get this out of the way ahead of time: if you're tinkering with your PC and you aren't prepared to deal with possible mishaps or other unintended consequences, you're doing so at your own risk! Now then -- enjoy!

Home

  • TripleSComputers.com

Tools

  • WUInstall

Donate to say thanks!

Has one of my posts helped you avoid headache or expense? Here's how you can say thanks!

Get it Done Right

If you're looking for computer help in the Louisville area, choose me and reap the benefits of a lifetime of knowledge. I don't lose data, and I rarely give up.

Disclaimer

You agree that use of the advice on this blog is entirely at your own risk and that this website is provided on an "as is" or "as available" basis, without any warranties of any kind. All express and implied warranties, including without limitation, the warranties of merchantability, fitness for a particular purpose, and non-infringement of proprietary rights are expressly disclaimed to the fullest extent permitted by law.

Recent Comments

  • Richard Gray on Solution: Can’t find script engine “VBScript” for script.
  • Milo Catharine on Solution: Can’t find script engine “VBScript” for script.
  • Terry on SOLUTION: Switch Windows 10 from RAID/IDE to AHCI operation
  • AntGut on SOLUTION: Skip Microsoft Account Requirement During Windows 11 24H2 Fresh Install
  • Steve Schardein on SOLUTION: Switch Windows 10 from RAID/IDE to AHCI operation

Find it Fast

  • advanced
  • antivirus
  • bad hard drive
  • bcd
  • blue screen
  • blue screen of death
  • boot problems
  • bsod
  • data recovery
  • dll files
  • DNS
  • driver
  • driver problems
  • drivers
  • error
  • error messages
  • errors
  • google chrome
  • hard drive
  • hardware
  • malware
  • networking
  • network problems
  • outlook
  • permissions
  • plugins
  • policy issues
  • printers
  • recovery
  • registry
  • registry cleaners
  • registry errors
  • rootkit
  • router
  • security
  • stop error
  • TDL
  • tdl4
  • TDSS
  • Trojan
  • vbscript.dll
  • video streaming
  • windows 7
  • Windows 10
  • windows update error

DISCLAIMER

The advice here is meant for education and reference only, and it is intended for professionals, NOT the average user. Much of it is advanced material. If you're tinkering with your PC and you aren't prepared to deal with possible mishaps or other unintended consequences, you're doing so at your own risk! You agree that use of the advice on this blog is entirely at your own risk and that this website is provided on an "as is" or "as available" basis, without any warranties of any kind. All express and implied warranties, including without limitation, the warranties of merchantability, fitness for a particular purpose, and non-infringement of proprietary rights are expressly disclaimed to the fullest extent permitted by law.
Proudly powered by WordPress