4 ms·
That's why the second, more advanced phishing page was trying to immediately log in with the just acquired login credentials. If a 2FA challenge is presented,
by dubbel 6y ago
That's why the second, more advanced phishing page was trying to immediately log in with the just acquired login credentials.
If a 2FA challenge is presented, it is relayed to the victim on the phishing website, and as soon as the code is submitted, is it relayed to the real banks website in turn.