8
Can we talk about how my 'secure' email still got me phished?
I used to think having a strong password and two-factor on my email was enough. Then last month I got a fake invoice from a company I actually use, and the link looked perfect at first glance. I clicked it, entered my password, and only realized later that the domain was off by one letter. The 2FA code I typed went straight to the scammers, and they used that session to reset my other accounts. What convinced me my setup was weak was reading how phishing kits now copy login pages in real time, even my password manager's auto-fill got fooled. Now I'm split between thinking hardware keys are the answer and wondering if just slowing down and checking every URL would have saved me. Has anyone else had a close call where a 'secure' habit still failed? What finally made you change your approach?
1 comments
Log in to join the discussion
Log In1 Comment
the_claire1mo ago
Damn, did the fake invoice come from a legit-looking sender address too?
1