Home/For the school team/Two-step verification

Security alert: what to do about an unexpected 2FA email

Ziber Team sends an automatic email when two-factor authentication (2FA) is enabled or disabled on your account. Receiving such an email and don't know where it came from? Read below what to do.

Did you do this yourself?

Yes? Then you don't need to do anything. The email only confirms that the change was made. You can delete the email.

No? Take this seriously — it may mean someone else has access to your account. Follow the steps below immediately.

What to do right away

1. Change your password immediately

Go to Account settings > Security and change your password. Choose a strong, unique password that you don't use anywhere else.

2. Check whether 2FA is still active

Look in the Security tab to see whether two-factor authentication is still enabled. If someone has disabled 2FA, enable it again right away.

3. Generate new recovery codes

If you suspect someone had access to your account, generate a new set of recovery codes. This invalidates any old codes an attacker may have seen.

4. Contact Ziber support

Let us know what happened so we can check your account for suspicious activity.

Why does Ziber Team send these emails?

Enabling or disabling two-factor authentication is a significant change to your account's security. The automatic email ensures you always notice it — even if someone else made the change. That way you can act quickly.

How can someone else change my 2FA settings?

This is only possible if they have your password and a valid verification code or recovery code. If you receive an unexpected email, it may mean that:

By changing your password and setting up 2FA again with new codes, you close off these risks immediately.

How do you prevent this in the future?

Good to know