• TerdFerguson@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    1 day ago

    They got the ai agent to send the password reset onetime code to a new address that they supplied through the chat.

    Effectively hijacking the pw reset and its safeguard. The users password did not need to be known