Easy to mitigate by only allowing the device that requested the 6-digit code to use the code.
Edit: See first reply, this is not a mitigation at all!
Edit: See first reply, this is not a mitigation at all!
The problem being exploited by BAD is that your login account identifier (email in this case) is used in both GOOD (and BAD - accidentally or deliberately orchestrated), and 2-factor does not prevent this type of phishing.