While contacting Roblox Support, I was asked to refile my case using the email address tied to my account, which confused me, as I had already been doing so. When the support agent provided a hint as to which email was connected to my account on their end, I realised that they were looking at the original email address that I used at the time of account creation, which was in 2014 (mentioning as I’m not sure if the fact that my account was created ten years ago had any role to play in this).
This is a serious security issue – too often are inboxes compromised, and when that happens, people update their accounts so as to minimise and mitigate further risks to their accounts. If Roblox Support relies on the original email address in order to verify a person’s identity, then such a hacker could then compromise an unsuspecting person’s account, even long after they’ve updated their email address in their account settings. In any case, it’s not reasonable to expect that a person should continue to have access to that inbox, if their email had been hacked or otherwise lost, in which case, they have no hope of proving their identity.
Although incredibly an frustrating one, it’s even more so a puzzling bug, since the Roblox website clearly shows my current email address in my account settings, and submitting a forgotten username request under that same email results in my account appearing, as expected (by this logic, I’ve assumed that this must be a bug of some sort, hence why I’m filing this report here).
Not sure if this is just an isolated issue (perhaps just related to my account or the support agent I had this once), but with millions of accounts out there, even if we were to presume that this was a once-off, that it is even happening to begin with is nevertheless a cause for concern.
Expected behavior
Roblox Support should be using the most current account records when verifying that an account belongs to someone.
A private message is associated with this bug report