Here's one tip for this expert – if you get a 2FA code over text or email that clearly has the line "we will never contact you for this code over phone or text" right under it, DON'T give it to a "support agent" over the phone.
> this is clearly a two-factor authentication code, meant to be entered directly into an authentication page. Which is normally not something that would be relayed over a phone call to a customer service rep. A concern that I raised to Daniel. However, he said that it was part of Apple's system, which they only had limited access to. An explanation that, as someone who works with computers, data security, and API integration professionally, I completely bought
And after reading multiple paragraphs of this person describing money literally taken out of their account in front of their eyes, you get to this line:
> Putting all of this together, the scales started to tip toward this potentially being a scam call, but I still wasn't certain
I really hope they don't have a lot of clients