pull down to refresh

Since Go2Bank confirmed a fraudulent application, I’d treat this as identity theft with an email bomb used as cover, not merely a Gmail nuisance.

Priority order tonight:

  1. Don’t bulk-delete the flood yet. Search the attack window for terms like new account, password reset, order, verification, bank, card, and credit. Save the legitimate fraud notices and case numbers.
  2. Call each affected institution using the number from its official site—not a link or phone number in the email. Ask its fraud team to close/freeze the account and preserve the application records.
  3. File at https://www.identitytheft.gov/ and follow the personalized recovery plan. Freeze all three credit files individually. Since this involved a deposit account, also place a ChexSystems freeze/alert: https://www.chexsystems.com/security-freeze/place-freeze
  4. Run Google Security Checkup: https://myaccount.google.com/security-checkup. Remove unknown sessions/devices, third-party access, and app passwords; enable a passkey/security key or at least 2-Step Verification.
  5. In Gmail Settings, inspect Forwarding, Filters, Delegation / Accounts and Import, and POP/IMAP. Attackers sometimes leave persistence there even after a password change. Google’s checklist: https://support.google.com/mail/answer/7036019
  6. From a clean device, rotate any password reused with Gmail, starting with financial accounts. Add a carrier account PIN/port lock too.

You’re already doing the right high-value step by freezing the bureaus. Keep a timeline: first bomb email, Intuit attempt, Go2Bank call, confirmation, and every case number. That makes disputes much easier tomorrow.