FlyerTalk Forums

FlyerTalk Forums (https://www.flyertalk.com/forum/index.php)
-   Chase | Ultimate Rewards (https://www.flyertalk.com/forum/chase-ultimate-rewards-722/)
-   -   Points stolen/ transferred (https://www.flyertalk.com/forum/chase-ultimate-rewards/2186258-points-stolen-transferred.html)

ajinlondon Feb 12, 2025 10:35 am


Originally Posted by mhdena (Post 36889462)
Do you have 2fa and the telephone password?

I added the telephone password just now, (also have a combined business login), the telephone password is only for when calling into Chase yes?

I do not have 2fa for Chase yet, I use the Chase app on my phone almost daily, will the 2fa need to be input each app login?

Seems the only thing that would stop this is the phone password being setup. 2FA wouldn't stop it. If you use the chase app and faceid 2fa doesn't slow down your current interaction so you may as well turn it on.

mia Feb 12, 2025 11:08 am


Originally Posted by mhdena (Post 36889462)
Do you have 2fa and the telephone password?

Chase enabled 2FA on my accounts sometime last year. I seldom use the smartphone app, but 2FA is not used when accessing the app, only the website. I created a telephone password yesterday while working on this thread. I seldom contact any card issuer by telephone, but my understanding is that the password is "only" used when calling.



gef100 Feb 12, 2025 3:11 pm


Originally Posted by ajinlondon (Post 36889822)
Seems the only thing that would stop this is the phone password being setup. 2FA wouldn't stop it. If you use the chase app and faceid 2fa doesn't slow down your current interaction so you may as well turn it on.


Even if CS gave a new password, 2FA is required to be authenticated on a new device. So do you have 2FA on or not?

ajinlondon Feb 13, 2025 9:58 am

Yes I have 2fa and your assumption isn't correct. 2fa is not required for this scam/ theft etc.
as above I in essence went through the same steps on the phone call with chase. "Here is the new password" and once they are into your account they update the personal details section. All very basic.

gef100 Feb 13, 2025 10:50 am


Originally Posted by ajinlondon (Post 36892298)
Yes I have 2fa and your assumption isn't correct. 2fa is not required for this scam/ theft etc.
as above I in essence went through the same steps on the phone call with chase. "Here is the new password" and once they are into your account they update the personal details section. All very basic.

2FA is required when logging into your chase account on a new device. Your device already has the cookies. Delete your cookies and you will see you are prompted for 2FA again.

ajinlondon Feb 13, 2025 4:00 pm


Originally Posted by gef100 (Post 36892443)
2FA is required when logging into your chase account on a new device. Your device already has the cookies. Delete your cookies and you will see you are prompted for 2FA again.

ok so how is it so in my app I can see the windows device scammer accessed my account and iPhone 11 - access my account . Neither devices exist within my home. And I repeat 2fa existed on my devices for a considerable time

gef100 Feb 13, 2025 4:20 pm


Originally Posted by ajinlondon (Post 36893096)
ok so how is it so in my app I can see the windows device scammer accessed my account and iPhone 11 - access my account . Neither devices exist within my home. And I repeat 2fa existed on my devices for a considerable time

I am simply pointing out that the process you have described is not empirical proof that 2FA was not triggered. You should remove any devices which are not associated with you. Additionally, in your chase account under 2FA is email enabled?

ajinlondon Feb 13, 2025 4:31 pm

appreciate the trying to be helpful. But you don't need to question the validity of what I am saying, been around / smart enough to know what's on and off. Yes I do get some folks this maybe a valid query. Not applicable here.
I have said numerous times 2fa is on / was on/ still on. The only security feature that Chase has added since is the phone password, which I feel the implementation is poor. Other banks "please hold whilst I transfer to the auto system and enter your secure password" vs Chase "please tell me your password" like thats real secure...

Yes - obviously removed the scammers devices. Chase folks did it, all a bit late. And again points to failures - multiple attempts to access over phone + access on brand new device + add a new phone number to my account = absolutely nothing from Chase.

I wish others well - I will be closing my account, as clearly the scamster downloaded some recent transaction details and I now have to deal with them trying to access those accounts as they obviously now garnered more info from Chase to help with my identity "picture". And Chase bank 'sorry' means nothing with 3 days of BS scam calls (also common as the scammer dumps your info to try and overwhelm your emails/ phone to divert your attention) along with trying to second guess what else they are trying to do..

notquiteaff Feb 13, 2025 5:59 pm


Originally Posted by ajinlondon (Post 36893157)
appreciate the trying to be helpful. But you don't need to question the validity of what I am saying, been around / smart enough to know what's on and off. Yes I do get some folks this maybe a valid query. Not applicable here.
I have said numerous times 2fa is on / was on/ still on. The only security feature that Chase has added since is the phone password, which I feel the implementation is poor. Other banks "please hold whilst I transfer to the auto system and enter your secure password" vs Chase "please tell me your password" like thats real secure...

So just to confirm (I admit I am a bit confused), what you are saying is that with 2FA enabled, your Chase account can (and was) accessed on new devices with a new password that was set by Chase customer service? That would seem to be a major bug in the 2FA implementation.

I just recently used a new iPad that, to the best of my knowledge, had never accessed my Chase account with the Chase app. And the app/site sent me a text code to my phone number.

ajinlondon Feb 13, 2025 9:05 pm


Originally Posted by notquiteaff (Post 36893298)
So just to confirm (I admit I am a bit confused), what you are saying is that with 2FA enabled, your Chase account can (and was) accessed on new devices with a new password that was set by Chase customer service? That would seem to be a major bug in the 2FA implementation.

I just recently used a new iPad that, to the best of my knowledge, had never accessed my Chase account with the Chase app. And the app/site sent me a text code to my phone number.

YES and if you have a look at Reddit / other forums will see it happened to others. Also just did a test to see if chase understands the difference between iPhone Safari version vs the app and it does. The history in the Chase app shows "iPhone 11 Chase app" which was the scammer along with a Windows machine a few minutes before the app was logged in. Lastly to highlight the stupidity, so they "merged" my points to another chase account, but isn't that only possible to family members/ household/ etc. If they get a class action/ audit of the procedures will be an F.


All times are GMT -6. The time now is 9:49 pm.


This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2026 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.