A new type of man-in-the-middle (MitM) attack enables malicious actors to perform password resets on victims devices. The attack site prompts the user to enter his or her phone number, ostensibly for verification. Next, the victim receives a security code from the target site in a text message. That code is then passed, inadvertently, from the victim to the threat actor, who can use it to harvest the reset password. Some sites use SMS-based two-factor authentication to add a level of complexity to the password reset process.”]