Skip to main content

I am not sure if this is the group to ask or not, but I work for a Nonprofit and while reviewing the Login History for the past 6 months, I noticed that a user who has been inactive since 2016, appeared to try to log into their SF account.  The login failed as the user is inactive, however, my question is more around would this be an attempt of someone getting a hold of an old email, username, password, etc and using this to try and login to our SF instance?  I do know it was from a Mac, it was Chrome and the IP address is from Clevland (or appears to be) and we are in Cincinnati.  Anyway, I am trying to determine if I should be concerned or note. 

 

#Security #Nonprofit

4 个回答
  1. 2月24日 21:31

    Hi @Heath Parks

    , i hope you should not as If the user is inactive and the login shows “Failed – User is inactive”, then No access was granted ,No password was validated No data was exposed. 

     

    This is usually one of three things:

    • A bot trying old leaked credentials
    • Someone testing an old saved password
    • Random automated login attempt

    You’d only worry if you see: Multiple attempts , Attempts across several users and Successful logins 

     

    Hope that helps  

     

    Thank you

0/9000