Maybe someone can explain this to me, I don't understand how they were able to get his account even though he had an OTP. He just got email confirmation to remove the OTP and that confirmation number was never put in. They still took it off and got his account.