Example of how not to send password reset emails

Example of how not to send password reset emails

5 years ago
Anonymous $9jpehmcKty

https://www.bleepingcomputer.com/news/security/stockx-password-reset-emails-are-legit-not-a-phishing-attack/

The StockX sneaker and streetwear resale site has started sending out emails to all of their users stating that they need to reset their passwords due to a system update. While these emails are legitimate, as they do not provide much details, users have been concerned that they are phishing attempts or their accounts are being hacked.

These emails have a subject of "Please reset your StockX password" and do not provide much info other than saying "We recently completed system updates on the StockX platform. To access your account, reset your password by clicking below."