An old Apple account I had mostly abandoned was compromised earlier this month. I still control the associated email, so I changed the password and enabled two-factor authentication. Despite that, the attacker has regained access and disabled 2FA four separate times.
I'm confident the email account itself is secure: I changed its password and enabled 2FA there as well. I also don't have any unknown Apple devices connected. The only linked device is a work phone that I added after the first compromise specifically to help secure the account.
What recovery method or attack path could allow someone to repeatedly disable 2FA after the password has been changed? Should I check for old recovery options, trusted phone numbers, security questions, or other account details? If I don't need the account, would permanently deleting it be a reliable solution, or should I secure something else first?
3 Answers
If you no longer need the account, deletion could be the cleanest long-term option, but only after you regain control and verify that the recovery information is yours. Otherwise, an attacker might still use an old recovery method during the deletion or security-change waiting period.
Check the entire account security page, not just the password. Look for unfamiliar trusted devices, phone numbers, recovery methods, security questions, and other account details, then remove anything you don’t recognize. After recovering the account, changing the sign-in email to a newly secured address may also help. Secure the account fully before attempting deletion.
If someone can repeatedly disable 2FA, there’s probably an older recovery method still attached to the account. Changing the password alone may not remove that access. The two-week security-change grace period and legacy security questions are worth investigating, since those may allow 2FA to be removed or account changes to be reversed.

That would explain why the password can be changed but the attacker still gets back in. Review and replace every recovery option you’re still allowed to change, especially the security questions and trusted phone information.