> Any company that authenticates customers with nothing more than static identifiers — address, SSN, DOB, phone number, credit card number, etc. — is vulnerable to these takeover attempts.
Does having two-factor auth even matter if it can be circumvented with social engineering from static data?