3 ms·
There's a great episode on ReplyAll podcast[0] about the methods for bypassing 2FA to snag accounts. Was the 2FA endpoint a SMS cell number? In that case, it's
by will_walker 6y ago
There's a great episode on ReplyAll podcast[0] about the methods for bypassing 2FA to snag accounts. Was the 2FA endpoint a SMS cell number? In that case, it's probable the thief fraudulently impersonated the victim to the cell service provider and phished the 2FA code. Sadly, the cell providers are the weakest link in that particular chain (probably much weaker than Facebook's security).
I also wouldn't put it past someone to guess a password or have reused a password with another service that has been hacked. Humans are terrible at password hygene.
[0] https://gimletmedia.com/shows/reply-all/v4he6k https://gimletmedia.com/shows/reply-all/v4he6k