QUOTE(WongTheThief @ Apr 23 2025, 11:19 AM)
If I were to guess:
The request for Telegram OTP is actually not for Telegram - but for Whatsapp, and gave away Whatsapp OTP instead
Try check whether that OTP received is actually for Telegram or Whatsapp?
Thanks for your detailed breakdown.
I can confirmed from the OTP sent to her phone is on telegram.
But after a day, there are two more verification code sent to her telegram. But those two I not sure is verify for what services as it just written down verification code.
She lost her WhatsApp account during we were sleeping. Because last online was about 1.30am and she found out the WhatsApp has been logged out at about 5.30am when wake up.
QUOTE(touristking @ Apr 23 2025, 11:41 AM)
This is what I am most afraid of, knowingly or unknowingly got something installed that cause security problem.
iPhone are supposed to be very secure but I think their main security relies on control of what apps you can install onto your phone.
Among Android, Samsung is probably the most secure but they work different via Secure Folder. I using Samsung primarily because of this feature. It is basically a sandbox with both hardware and software protection. Being a sandbox, it is "cut" off from other part of the unfortunately infected phone.
So good idea to find any other Android phone with such feature.
I never know for such feature like sandbox from Samsung. Really good to know, thanks for your sharing.
Do you know any feature that can enhance security on iPhone ecosystem?
QUOTE(poweredbydiscuz @ Apr 23 2025, 11:57 AM)
If you wife can fell into that kind of trap, I won't be surprised if she actually forgot/confused/mistaken the whatsapp OTP as telegram. Even worse, she may have given out more OTP than you know.
She gave out OTP at 4.30am Tuesday and hacker gain control of her account for about 48 hours. But she only lost her WhatsApp today 3am.
I did see she received verification code twice on telegram. But not sure the verification code is for what
QUOTE(Xploit Machine @ Apr 23 2025, 12:03 PM)
dont click or answer unknown URL / calls .. activate 2FA

Is it possible they hack through call?
Because usually I just pick up any calls as we’re working and sometime new client would call up for potential deal.