Quote Originally Posted by LittleArrow View Post
Maybe someone can explain this to me, I don't understand how they were able to get his account even though he had an OTP. He just got email confirmation to remove the OTP and that confirmation number was never put in. They still took it off and got his account.
That doesn't make sense to me either, if the attackers tried to log onto the official site to reset his account, they would have been asked for a one time password which they wouldn't have had?