you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 2 years ago (1 child)

I'm talking about TOTP in something like Bitwarden or Authy. You can still social engineer your way to getting a code, but a scammer would have to convince the user to reveal that secret, not just pretend to send a code.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago*

    It sounds like in the above case the codes were real 2fa codes from his bank as the scammers were resetting their login credentials then adding an external account to initiate a transfer. Presumably they were simply reusing info from a breach to make the scam smoother

  • source
  • parent