I don't see how "contacted a friend" enables an exploit - in this case (and many others I've heard on the 'net) this channel only provides info or verification about the breach, and specifically doesn't provide, and IMHO won't provide, either of (a) any security credentials or (b) resetting any security credentials.
The question isn't about how to authenticate yourself to the friend at the company, the issue is that the friend in the company shouldn't (and shouldn't be able to) perform privilege escalation. They can tell you what has/hasn't been done with your account, but then you have to login or reset password the normal way in any case.
Comments
I don't see how "contacted a friend" enables an exploit - in this case (and many others I've heard on the 'net) this channel only provides info or verification about the breach, and specifically doesn't provide, and IMHO won't provide, either of (a) any security credentials or (b) resetting any security credentials.
The question isn't about how to authenticate yourself to the friend at the company, the issue is that the friend in the company shouldn't (and shouldn't be able to) perform privilege escalation. They can tell you what has/hasn't been done with your account, but then you have to login or reset password the normal way in any case.