Good Job.

I will explain the 2FA to you. If they DIDNT log in your account through RuneScape, you WONT get notified - so what they did was go on your email FIRST and then this gives them power on 2FA, it will NOT notify you someone has requested to change your 2FA through the Authenticators email owner. 2FA only pings if somebody tries to log in through RuneScape, it doesn’t alert anything else.

As for the bank pin, they guessed it - why? I have no clue that is ridiculous, they had 3 years to wait 7 days to disable it but they obviously cbf waiting and went through combos until it hit it. There’s no other way they can know your pin besides those two options, unless you told them or wrote it in your RuneScape notes

/r/runescape Thread Parent