https://nakedsecurity.sophos.com/2023/02/27/beware-rogue-2fa...
They don't look at API calls made by the apps. How can they be your sure of the security then?
Only after this was published were the apps removed.