Quote Originally Posted by Valkyrie_Lenneth View Post
Nah, they capture the code with the fake login site then immediately enter it into the client. That's how they login.


2fa won't help you if you give them the code lol.
That's also assuming the site that you are "logging" into has the spot to enter 2fa. If they don't, then there would be no way to get into the account. As I haven't even looked at those phishing links, I don't even know if they have a field for that.