Why SMS codes stopped being enough
Modern phishing pages act as a live relay. When you type your one-time code into the fake page, it is forwarded to the real site within seconds and the attacker's session is established. The code was valid, you entered it yourself, and nothing on your device was compromised — which is why this defeats awareness training alone.
What actually stops it
Domain-bound authentication. Passkeys and FIDO2 security keys will only respond to the genuine domain, so a relay page receives nothing usable. Where that is unavailable, push approvals with number matching are a meaningful improvement over typed codes.
- Prefer passkeys or a hardware security key on email and financial accounts
- Treat any login page reached from a link as suspect; navigate to the site yourself
- Be alert to approval prompts you did not trigger — deny, then change your password
- For teams, enforce phishing-resistant methods for administrators at minimum
If you think you approved one
Change the password, sign out all sessions, check recovery settings and mail-forwarding rules, then re-enrol your second factor. Forwarding rules are the step most people miss, and they are how an attacker keeps reading your mail after you lock them out.