@SwiftOnSecurity This sounds like the nightmare scenario for phone-based #2FA and account recovery that we’ve been warning people about for years