{"success":true,"data":{"id":"otp-intercept-account-takeover-phish","label":"Fake security alert asking recipient to share or enter a one-time passcode/OTP by email — real providers never request OTP codes over email; this is an account-takeover interception attack.","description":"Fake security or account alert asking the recipient to share or \"enter\" a one-time passcode (OTP) by replying or clicking a link — account-takeover (ATO) interception attack. Real service providers send OTPs for the user to enter on their own login page; they never email asking the user to email the code back or share it externally. The attacker triggers a real login attempt, intercepts the OTP, and takes over the account. Detection: one-time code/OTP/verification code vocabulary + enter/share/provide/reply-with code action + no List-Unsubscribe + no In-Reply-To + not protected sender. Trash score: +4. Source: GC1-R21; CISA ATO advisory 2025; Okta SIM-swap intercept pattern.","tier":"danger","category":"phishing","isThin":false}}