> If you were targeted with such a phishing attack, you'd fall for it too and it's a matter of when not if. Anyone who claims they wouldn't is wrong. I like to think I wouldn't. I don't put credentials into links from emails that I didn't trigger right then (e.g. password reset emails). That's a security skill everyone should be practicing in 2025.
Yeah, I feel that bit is just wrong, in three ways for me: 1. Like you, I never put credentials into links from emails that I didn’t trigger/wasn’t expecting. This is a generally-sensible practise. 2. Updating 2FA credentials is nonsense. I don’t expect everyone to know this, this is the weakest of the three. 3. If my credentials don’t autofill due to origin mismatch, I am not filling it manually. Ever. I would inste…
The problem with this is that companies often send out legit emails saying things like "update your 2FA recovery methods". Most people don't know well enough how 2FA works to spot the difference.