
Time to reconsider your security policies and prevent scams
As of right now a user can sign up with someone else's email address without their permission and use a burner phone for text verification. This is a serious security risk against fraud and people using stolen credit cards to access your services. This happened to me.
I sent an email (shown in this image) to Intuit CreditKarma's security department asking them to unlink my email from any accounts there because I don't have an account with them but someone signed up with my email. I figure some scammer used my email address and their own phone number so they don't have to leave evidence of their scam/fraud, because the site requires an email. Instead of just unlinking my email, the Intuit CreditKarma security person asked for my full name, date of birth and last four digits to my SSN. As if I would ever give them that and why would I if they can just unlink my email address!
Perhaps there is a way to verify a user sending an email is the person who owns the email? I don't think you can spoof an email and receive replies to that email, so if there is a way to handle these types of security vectors I would appreciate my email being removed from my account without having to provide any personal information.