My financial institution advised changing passwords after insuring that my PC is cleaned of any viruses. I've done this but an Amazon rep recommended that I also change my email address. Is this good advise and why or why not? Thanks!
Hi @Mickey_108
They probably mentioned that as a extra security precaution. IMO, what is just as important, is enabling 2FA, which Amazon allows in your account settings page. I personally use the 2FAS phone app.
I have 3 email accounts.
1) was my Gmail account from years ago, when I first set up an email account. It is where the spam tends to land after years of vendors servers being hacked. If I ever get a email from my bank or financial vendors in this account, I know it's spam as all those critical sites have my 2nd email address…
2) is only used for my banking and financial accounts. That has yet to have been compromised. I use a Proton email account for that one.
3) the 3rd one is a bit of updated email address for sites I only want to allow with this account (is a 2nd Gmail account). It hasn't been compromised, either. It would be the one to consider for sites like Amazon, etc.
I hope this helps in some way.
Scott, many thanks for the helpful and kind advice! I was thinking the 2 factor procedure should be adequate.
And it very well could be, it just depends on your comfort level, as the financial institutions didn't mentioned using a different email address? Amazon is huge worldwide, so again, it may be them erroring on the side of caution.
I may be taking things to the next level, but for the financial and banking vendors, you may want to consider that 2nd email, from what I mentioned in 1) & 2)? But, that's up to you :)
This post actually inspired me to write the below article. Check it out:
Regards
@Mickey_108
I forgot about this thread. Maybe you'll find some useful information over there?
I'm very grateful to Scott and Alexandru for the helpful advice! My clean up is apparently almost 100%. The crook didn't achieve any financial gain but I'd definitely like to see accountability for their mischief and taking my time. Just one dangling matter at this point. I've received 3 OTP's from X, with whom I don't have an account. My understanding is that in this situation it's best to not respond at all and just delete the message.
You're most welcome. Yes, I also think it's best to delete that message.
if you have an Apple or a (free) Tuta mail account, you can set up aliases for all of the companies you do business with.
I use Tuta mail. For each online site, I create an email alias using the site uri. For example, for PDQ bank, I create the alias pdq.com@mydomain.com.
If get spam from PQD or if your information is otherwise compromised, you can quickly suspend the email, investigate, and reactivate or delete the email entirely.