🟠 High  |  Source: Schneier on Security


A first-person account details how a victim lost control of their email account after being socially engineered into handing over a two-factor authentication code. The incident illustrates how a single compromised email account can cascade into full identity theft, as most online accounts rely on email for password resets and recovery. This is a stark reminder that MFA codes are as sensitive as passwords and must never be shared.

Security Architect’s Take: Audit your organisation’s account recovery flows to ensure email compromise cannot trivially unlock downstream SaaS and cloud accounts; consider enforcing phishing-resistant MFA (FIDO2/passkeys) where possible, and educate users that legitimate services will never ask them to relay one-time codes received via SMS or authenticator apps.

Original advisory: First-Person Identity Theft Story