FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   American Airlines | AAdvantage (https://www.flyertalk.com/forum/american-airlines-aadvantage-733/)
-   -   2 factor authentication (https://www.flyertalk.com/forum/american-airlines-aadvantage/2073174-2-factor-authentication.html)

jordyn Aug 17, 2022 3:26 pm


Originally Posted by MASTERNC (Post 34522772)
Our IT training just showed how someone can even avert the push notification 2FA by directing you to a bad website, capturing the cookie data fed back after the 2FA, and then pasting it into the web browser code. Nothing is perfect.

This is why state of the art for 2FA is U2F, which is also resistant to phishing attacks. This video explains how it works:


jordyn Aug 17, 2022 3:29 pm


Originally Posted by EXP100 (Post 34106767)
Is it just me but I have no desire when I'm trying to pull the app up in the airport/AC for any number of reasons and needing to get a code text to me to do so.

The idea isn't that it's something you desire to do in your daily workflows, but that you desire for a hacker to be unable to do it when they somehow get hold of your password. As with many security features, they add some amount of inconvenience, but the best versions (e.g., U2F) aim to minimize that inconvenience while maximizing the security value.

PHL Apr 8, 2023 10:37 am

I learned at 7am today that someone hacked my account when my password was failing and I saw emails from 6am that my password and account info was updated.

I was able to get back in with my security questions and found a name, address, phone and email in the UK was attached to my account. I changed my info back, updated my password and security questions.

Points were not taken and future trips were still in tact. It was at this point I searched for MFA options but, as mentioned upthread, this is not a priority for AA.

Did I catch the issue quick enough (1 hour) that the hacker didn’t have time to muck with my account? Or should I be worried they may already have info they need to call in and redeem trips over the phone?

Catbert10 Apr 8, 2023 12:21 pm

I don't think 2FA is a big deal among airlines given that reservations can be accessed online without any authentication at all.

VegasGambler Apr 8, 2023 4:57 pm


Originally Posted by PHL (Post 35153848)
I learned at 7am today that someone hacked my account when my password was failing and I saw emails from 6am that my password and account info was updated.

I was able to get back in with my security questions and found a name, address, phone and email in the UK was attached to my account. I changed my info back, updated my password and security questions.

Points were not taken and future trips were still in tact. It was at this point I searched for MFA options but, as mentioned upthread, this is not a priority for AA.

Did I catch the issue quick enough (1 hour) that the hacker didn’t have time to muck with my account? Or should I be worried they may already have info they need to call in and redeem trips over the phone?

You should definitely call AA about this. They definitely have all the info they need. It really isn't very much info.

alexrubens Apr 9, 2023 11:11 am

Mine was hacked a year or two ago — they found the guy who did it and used all the miles, but said I had to report it to local police in his jurisdiction and they wouldn’t refund the miles until something substantial happened… I had to get a new AAdvantage number and everything.

jmrp Jul 13, 2023 7:43 pm

So......this happened to me this morning (07/13/23):

https://viewfromthewing.com/american...tage-accounts/

I had logged in late last night (07/12/23) (more than once) just fine, like normal.

This morning I logged in like usual on the Login page, BUT...... instead of actually logging me in it took me to a page w/ 6 small boxes asking for my verification code that it had emailed to me. I checked my email & sure enough there was an email from American Airlines.

Once I copied/pasted the code I was then in like normal (w/ my name in the light blue box up top.

No warning this was coming. I thought I'd been spammed at first. UGH, what a pain !!


https://cimg0.ibsrv.net/gimg/www.fly...705b00552a.jpg

Pinned Jul 14, 2023 10:39 am

Pain?! This is the best thing American has done for their IT in years. The amount of accounts getting hacked (that will now more easily be prevented) is huge.

WeekendTraveler Jul 31, 2023 6:56 am

Suddenly two-factor authentication is required on my AA account.

At least I was able to access my email account at the same time, which was significantly less frustrating than an experience with Target on the same day: Target required the same suddenly as I was in the process of trying to pay with my phone at a self-checkout device.

Perdita Jul 31, 2023 7:29 am

I was asked for the verification code on my most recent login. Will I be asked every time now for a new code or will it be only randomly during logins?

dc10forlife Jul 31, 2023 8:27 am

I'm curious how this will be implemented with the AA app and when accessing the app/web site while in-flight. Without buying in-flight wifi internet access, getting the code from an e-mail will not be possible.

jmrp Jul 31, 2023 1:55 pm


Originally Posted by Perdita (Post 35458920)
I was asked for the verification code on my most recent login. Will I be asked every time now for a new code or will it be only randomly during logins?

Since this 1st happened to me as I posted above (07/13), it happened almost every time I logged in over those next few days. It hasn't happened to me since 07/15.

I do almost always log into AA w/ Firefox on my home computer. Maybe some cookies or something are saved. We'll see going forward.

I also always keep track of my husband's AA stuff (both our trips together & his work trips w/o me). I usually use Chrome to log into his AA acct (just so I don't have to keep re-entering our login info in Firefox every time). I just logged in as him in Chrome & it still has not asked for a verification code.

TheDudeAbides Mar 8, 2024 3:20 pm

Logged in twice today. Both times I was asked for a verification code. First time it has ever happened to me. What a pain in the rear. VPN related, maybe? I hope this isn't going to happen every.single.time that I log in.

Antarius Mar 8, 2024 4:18 pm


Originally Posted by TheDudeAbides (Post 36064766)
Logged in twice today. Both times I was asked for a verification code. First time it has ever happened to me. What a pain in the rear. VPN related, maybe? I hope this isn't going to happen every.single.time that I log in.

It's started for me too. Although its intermittent. 3 out of 4 maybe?


All times are GMT -6. The time now is 7:32 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.