If 2FA is enabled on your account and you've lost access to your method - your phone died, your authenticator app was wiped, you can't get into your email, or you changed phone numbers - here's how to recover access.
Try these first
Before contacting support, check whether you can still get a code another way:
Authenticator app - If you backed up your authenticator app to the cloud (Google Authenticator backup, 1Password sync, Authy multi-device), restore it on your new phone first.
Email Code - Make sure you can still sign in to the email address on your Loophole account. If you've moved providers, regain access to that inbox first.
SMS Code - If you still have your old SIM, your old phone, or your carrier can forward texts to your new number, you may still receive the code.
If none of those work, you'll need our help to disable 2FA on your account.
How to request 2FA reset
Send an email to Security [at] Loophole (dot) com with the following:
Send the email from the address on your Loophole account.
This is how we verify it's really you. Requests sent from any other email address will be denied.Subject: "2FA Reset Request"
In the email, include:
The email address on your Loophole account (so we can locate it)
Which 2FA method you had enabled (Authenticator App, Email Code, or SMS Code)
A brief explanation of why you've lost access (lost phone, changed numbers, app wiped, etc.)
We may follow up to confirm a few additional account details before disabling 2FA.
What happens next
Our security team reviews 2FA reset requests within 24 hours, typically much sooner
Once your identity is confirmed, we disable 2FA on your account
You'll receive a confirmation email at your account address letting you know
You can then sign in with just your password
Strongly recommended: As soon as you're back in, head to Settings β Security and set up 2FA again with a method you can keep access to.
If you don't hear back within 24 hours
Check your spam/junk folder for replies from [email protected]
Make sure you sent the original request from your account email - requests from other addresses are not processed
If both of those check out, send a follow-up to Security [at] Loophole (dot) com referencing your original request
Why we don't offer self-service recovery
The whole point of 2FA is that no one - including someone who has your password - can sign in without the second factor. If we let users bypass 2FA with a simple form or a link, that protection would mean nothing.
Manual identity verification by our security team is what keeps your account safe even when you've lost your second factor.
Once you regain access, please re-enable 2FA. An account with 2FA on is dramatically harder to compromise than one without it.
