> The thing that's crazy is that if I followed the 2 "best practices" of verifying the phone number + getting them to send an email to you from a legit domain, I would have been compromised.
The best practice I live by is always call them back yourself. Looking up the phone number is not the same.
The best practice I live by is always call them back yourself. Looking up the phone number is not the same.