Go figure, this is like spit in my face after Jagex basically said "tough luck" to getting hacked and losing a yellow phat several months back, despite their lack of security for third-party account linking (that's an issue by the way; I noticed it wasn't listed in the changes on the news update).
Even though they were informed within 10 minutes of the issue happening, as I actively fought the offender off my account repeatedly, with the lack of security being in their court, nothing was done. I even asked if they would look into the offender and ban them. Their response was, instead, that there's "nothing they can do" but not because they couldn't - rather they wouldn't.
So now that you're reading this;
Jagex, if you're listening
: Require the authenticator both for regular login
as well as for third-party account logins.
Thanks, I hope that slips in with these account security updates rather than being overlooked. It's an incredibly huge security risk, and as an IT professional who works close with security and device hardening, I'm still utterly stunned that such an obvious exploit/vulnerability around 2FA exists for RuneScape. Breaks my damn heart tbh.
Oh yeah, and considering I put some bonds towards a fair portion of the partyhat cost at the time, a little disappointed in the lack of commitment to me as a customer.