On the one hand we don’t want to be saying anything that provides information an attacker could use to try to find valid accounts to try to break into, but I agree that’s not a great experience. However, I wasn’t able to reproduce it here with a current Stacker app, only a legacy one using Customer Access. It’s not an issue on the New User Model, so if you’d like to update just shoot us an email at
support@stackerhq.com and we can look at the options with you.