. . "Have good logging on all account reset transactions, and have a human being actually monitor these and act if they appear suspicious (look at the server logs for the IP addresses fx, do many requests come from the same IP address, are there instances were a user is trying to reset passwords from a country different from the registered account owner's etc)." . .