> Mitch said his financial institution has in the past verified his identity over the phone by sending him a one-time code to the cell phone number on file for his account, and then asking him to read back that code.
The advice from Krebs about phone calls is never talk to "the bank" (etc) when they call you, always you have to call them back. But the bank _will_ really sometimes contact you "out of the blue" to ask you about potential fraud on your account. You just have to hang up and call them back, you can't tell the difference based on "reasons".
It is very hard for the end-user to tell what 2FA request is "for no reason". I think we need to focus not on what the "reason" is or if it's "out of the blue", but, the equivalent of "call them back" for online too -- don't click on a link in an email, etc.
No matter what, it's not easy, especially for less technical users. The linked account is a security professional that fell for it -- I personally don't have the hubris to think I never would.
There have been times when an actual bank asks me to do something I know is insecure, and I consider resisting it, but I just didn't have the energy for it, I figured it really was the real bank just being idiotic and I wanted to get on with my day (and guess what, it was, I was right).
[1]: https://krebsonsecurity.com/2020/04/when-in-doubt-hang-up-lo...