Hacker News new | ask | show | jobs
by pluc 275 days ago
You're right, seems they already had his inbox credentials.
1 comments

No, it sounds like they got him to create backup codes, which (along with SMS 2FA code, which he also gave them), that is all they need to take over the gmail account. Job done.