Quote Originally Posted by Ravenblade1979 View Post
Make one time password mandatory.
That wouldn't necessarily help because the fake log-in page demands your OTP...which in itself should be a tell that the page is phony because the official log-ins ask for your OTP after it determines your account name/password are correct, not at the same time.