Hackers Pull Off $12,000 Bitcoin Heist
wired.com
wired.com
Or even just post the text as a comment. Thanks.
You don't really need technical skills to convince a service provider to give you access you shouldn't have, when the original signup's security answer was publicly available information.
This attack vector was exactly how Sarah Palin's Yahoo mail account was "hacked" in the 2008 presidential campaign. So you'd think people would be more careful nowadays...
It's interesting to me, because "socialing" DNS and other providers generally isn't in-scope during pentesting.
Would be interested to know if there are any pentesters / firms who have this in their "standard" methodology, for webapp or external network testing.