08/16/2026
Account takeovers are still out of control.
The caller claimed to be Google Security, said the location looked suspicious, and asked the user to confirm a two digit code inside Google Photos. It belonged to Google's own sharing flow, which is why it felt legitimate. Right after, the user read back the six digit code that followed. That code was her two factor authentication credential and reading it aloud handed her Gmail account to the attacker.
From there the attacker set up a mail filter meant to hide replies from view. We jumped in immediately. A Backgrounder review found it was configured but never used. Access lasted several hours before we stepped in, reset the password, and moved her off SMS based verification entirely.
Simplest lesson here is no legitimate company will ever call and ask you to read back a verification code. If that happens, hang up.
What we recommend for everyone, not just this client. Use an authenticator app instead of codes sent by text or voice. Assume your email already appears in a breach dataset, because it probably does. Put a scam call and text blocking tool on your phone which will be Ask Carmen Guardian in a couple of weeks! Look into a personal information removal service to cut your exposure on data broker sites. We like Freeze and Optery! For password management we recommend 1Password.
These attacks are automated and opportunistic, running at scale against thousands at once. It rarely takes a sophisticated attacker. It takes one moment of trust.