WaTech's Office of Cybersecurity is seeing a new phishing campaign that tries to trick people into revealing their work login credentials. The twist to this campaign is that it also tries to trick users into authorizing a two-factor authentication request that allows bad actors access to their accounts.
Here's an example of what we're seeing:
1. A phishing email says you…