Quote Originally Posted by MsMisato View Post
To be honest, get 2-factor authentication. They can't log into your account unless they have your token. worst case is your account gets locked due to many attempts and you have to follow the instructions SE sends you.
It would not have helped in this case. If you enter that two factor code from the token into the phisher’s website, they now have the code, and can use it to get your account.