BT Email users hit by barrage of unsolicited password reset PINs
- ID
- 24991
- Status
- summarized
- Published
- 16 Sep 2026, 5:15 PM
- Fetched
- 16 Sep 2026, 5:21 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/networks/2026/09/16/bt-email-users-hit-by-barrage-of-unsolicited-password-reset-pins/5296616
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 2.0
- Created
- 16 Sep 2026, 5:21 PM
- Tags
- Audience
- developers
What happened
BT Email customers have reported receiving hundreds to over 1,000 unsolicited password reset PIN messages in rapid bursts since the weekend, with BT investigating but offering no explanation. BT says accounts are secure and no action is needed, though at least one unverified customer claim suggests an account takeover occurred during the PIN flood.
Why it matters
Little direct relevance to this audience. The cause is unknown, the impact is consumer email at a UK telco, and there is no confirmed breach or technical detail to learn from. The only practical takeaway is a cautionary one: if you build password-reset flows, consider rate-limiting and anomaly detection on reset requests to prevent similar abuse or noise.
Discussion angle
Brief mention only: what rate-limiting or throttling patterns on password-reset endpoints would prevent a similar flood, and whether SMS/email OTP reset flows are inherently abusable.