New MFA Phishing Scam Lets Criminals Use Your Own Login Approval
OTP scams are no longer limited to criminals calling and asking for a code. A newer method uses fake login pages that closely copy a bank, workplace or social-media account. After you enter your username and password, the fake page relays them to the real service. The real service then sends a genuine OTP or login-approval prompt to your phone. If you approve it, the attacker can access the account using your own confirmation. This method is known as MFA phishing or an adversary-in-the-middle attack. Similar tactics were used in breaches involving Uber, Cisco and Reddit. Some attackers also flood victims with approval requests until they mistakenly tap “approve.” Never approve an OTP or login request you did not initiate. Check links carefully, use official apps or bookmarked websites, and report unexpected prompts to your bank or workplace IT team. Have you ever received an OTP or approval request when you were not trying to log in?
Stories are shared by community members. This article does not represent the official view of NaijaWorld — the author is solely responsible for its content.

