No Link to Click: How a Text and a Phone Call Defeated MFA
No link was clicked. No malware was installed. No email gateway was crossed.
A software development director lost her account in under two minutes.
This is the full chain, in real time: a text message that offers to prevent a
problem rather than asking for anything, a phone number she dials herself, a calm voice that explains what she is about to see before she sees it, and six digits read out loud.
Watch what the platform does. iOS flags the sender as unknown and offers to delete the message. The verification code arrives from her real identity provider, carrying its own warning not to share it. Both warnings are on screen. Both lose — because by the time they appear, a helpful stranger has already told her to expect them.
Nothing here required a breach. The attacker knew her name and that she used an iPhone. Neither is a secret. Her password was already gone, taken somewhere else on the real login page. The passcode was the last door, and she held it open long enough to read it aloud.
DRAMATISED RECONSTRUCTION. The company, the employee and all footage are fictional and were created for this film. The attack chain is not — it is the pattern behind a large share of enterprise account takeovers on mobile.
CHAPTERS
0:00 The text message
0:20 She calls the number herself
0:50 "Before I touch the account, I have to verify it's you"
1:16 Six digits, read aloud
1:46 What happens on the other side
2:10 Where this gets stopped
MITRE ATT&CK
T1660 Phishing (Mobile) — the smishing message
T1598.004 Spearphishing Voice — callback phishing, the victim dials the attacker
T1656 Impersonation — "this is Dan from the IT service desk"
T1111 Multi-Factor Authentication Interception — the out-of-band code
Learn more: https://www.lookout.com/platform/social-engineering-protection
#MobileSecurity #Smishing #Vishing