Security experts are inviting users to avoid sharing login credentials on multiple websites and to enable two-factor authentication (2FA) when it is available. Security expert Alex MacCaw, co-founder of Clearbit firm, warned of an attack technique observed in real attacks. The attacker sends a Google user a text message pretending to be the company, pretending to appear a legitimate service provider. The hacker uses the victims credentials and the 2FA obtained through the above process to access the account. The victim in order to avoid problems sends the code back, believing they have thwarted the attempted hack.”]
Source: https://securityaffairs.co/wordpress/48286/cyber-crime/two-factor-authentication-hack.html