Why did they need to call? They could’ve phished the password and MFA by simply MITMing?
Perhaps we need a distinction from phishable MFA and unphishable U2F/WebAuthn style
Perhaps we need a distinction from phishable MFA and unphishable U2F/WebAuthn style
> The additional OTP token shared over the call was critical, because it allowed the attacker to add their own personal device to the employee’s Okta account, which allowed them to produce their own Okta MFA from that point forward.
They needed to have a couple of minutes to set things up from their end, and then ask for the second OTP code. A phone call works well for that.
That is indeed interesting; keep the con going a bit longer to get a proper foothold.