V
2

One bad phishing email in Seattle changed my whole approach to MFA

Last Tuesday I almost fell for a fake Microsoft login page. It came as a calendar invite from someone I actually work with. I clicked it during a rushed lunch break and typed my password. Then the real security alert popped up 10 minutes later. I caught it before they got in, but it shook me. I used to think MFA was just extra friction, now I see it as my only real safety net. Has anyone else had that wake up call moment where you finally stop ignoring those setup prompts?
1 comments

Log in to join the discussion

Log In
1 Comment
nina_hall48
That line about MFA being "just extra friction" hit me hard because I used to say the exact same thing every time I got a setup prompt. I figured my password was strong enough and I was too careful to click something dumb. Then my wife's cousin lost his whole work laptop to a similar phishing trick and I still shrugged it off, figured that was on him. But reading how close you got, and that it was a calendar invite from a coworker, that's exactly the kind of thing I'd fall for on a busy day. Now I've got the app on my phone and I actually look at those alerts like they're a lifeline instead of an annoyance. It's crazy how one close call can flip your whole view around.
-1