An old Apple account I had mostly abandoned was compromised earlier this month. I still control the associated email, so I changed the password and enabled two-factor authentication to regain and secure the account. Despite that, the attacker has managed to disable 2FA and take control again four times.
I'm confident the email account itself isn't compromised: I changed its password and it also has 2FA enabled. I don't have any personal Apple devices besides a work phone, which I linked only to secure this account after the first takeover. The account currently shows no unfamiliar trusted devices.
Could there be an older recovery method, security question, trusted phone number, or other account setting that lets someone bypass 2FA? What should I check or change, and would permanently deleting the account be a valid solution once it's secured?
3 Answers
Make sure the attacker hasn’t changed the security questions or another recovery detail. Two-factor authentication changes can involve a temporary grace period, so someone who already knows the older security answers may be able to disable it before the change fully takes effect. Keep monitoring the account, replace every unfamiliar recovery method, and contact official support with the repeated takeover history if the settings continue reverting.
Repeatedly disabling 2FA usually means there’s still an older recovery path that existed before 2FA was enabled. Security questions or a recovery method may be allowing the attacker to start the 2FA removal process during the grace period. Changing the password alone won’t help if that older mechanism is still available, so update or remove every legacy recovery option you can find.
Check the entire account security page, not just the password and trusted devices. Look for unfamiliar recovery methods, trusted phone numbers, security questions, linked devices, or recently changed account details. If you regain control, remove anything you don’t recognize and consider moving the account to a separate, fully secured email address. Deletion may be the cleanest option if you no longer need the account, but secure it first so the attacker can’t interfere with the process.
There don’t appear to be any unknown trusted devices, but I’ll review every recovery option again and try switching the account to a different secure email address.

If the account is already using 2FA, some older security-question options may no longer be editable. That makes checking the account’s recovery information and waiting out any 2FA removal period especially important.