Comment by junon

3 months ago

That was the low-tech part of their attack, and was my fault - both for clicking on it and for my phrasing.

It wasn't a single-click attack, sorry for the confusion. I logged into their fake site with a TOTP code.

This is a clear example that this can happen to anyone.

Sorry for what you're going through.

  • This is why Passkeys are getting pushed right now. They make it physically impossible to sign in to a phishing site.