Someone logged into my Etsy account and replaced the profile picture with the Etsy logo and changed the name also, and then sent hundreds of messages to new stores, and when I noticed this when I woke up, I changed the password and I formatted the windows.
Now I have lost the Seller badge and I am afraid that they will report my account and maybe etsy will suspend my account...
I don't know how they got into my account Knowing that I have the Two-factor Authentication turned on
please tell me what should i do please!
Hello,
The ETA for response varies on a case-by-case basis, and your ticket is being handled by a separate team. Please stay tuned to your email as any further communication on the matter will take place through there.
Since this case is already being worked on, we'll close this thread. Thank you.
Yeah, this is how the scammers have been messaging shops.
You've changed your password which is good. Now you need to make sure the hackers are signed out by going to your sign in history page and checking all devices.
https://help.etsy.com/hc/en-gb/articles/115015569567-How-to-Make-Your-Account-More-Secure
You also need to figure out how they got in. I would run an antivirus program to check your device for malware (e.g. keystroke loggers) otherwise they could try again. Make sure your 2 factor authentication is actually working and download the back up codes.
I have done all this and now I cannot respond to customer messages. i don't know How long will it take to solve this problem
Hello,
The ETA for response varies on a case-by-case basis, and your ticket is being handled by a separate team. Please stay tuned to your email as any further communication on the matter will take place through there.
Since this case is already being worked on, we'll close this thread. Thank you.
If you haven't done so already, you may want to consider getting in touch with Etsy to let them know what happened. Be very clear that you have regained access to your account (so they don't close it now thinking it's still hacked), but that for a time period changes were made and messages were sent. If they can block accounts based on the IP address, then they should be able to confirm that someone somewhere else was logged into your account. As Amaradorn said, make sure you go into your security settings and logout anyone that's not you.
I know when sellers have had issues with buyers and given them a head's up, when the customer later put in a complaint, they weren't immediately refunded like they otherwise would have been. In this scenario obviously you want them to somehow remove and disregard messages sent during that time. Now whether they'll actually go that far or not, I couldn't say. And contacting them could confuse them and they'll now suspend your shop, basically there's really no good option in this scenario.
It is scary that they were able to access your account even with the 2FA. I know no system is perfect, but that's scary if they're breeching that.
I don't believe anyone can give you any realistic time frame for this to be resolved as it's (hopefully) not a common occurrence.