Kenneth.J_24
Member
Same here, the access code thing caught my attention too.Yeah I saw something similar floating around security Twitter earlier this week. Idts it was the exact same report but the vibe sounded close. The whole access code step feels kinda sus because most real document tools already authenticate through their own system. Could be attackers trying to filter real humans from automated scanners. Periodt.
I am not in cybersecurity either but it kind of feels like phishing campaigns are getting more layered lately. Instead of just sending a bad link they add these extra stages that look official. That probably makes people pause less because it feels like a normal verification step.