| CPC H04L 63/1483 (2013.01) [H04L 63/0838 (2013.01); H04L 63/126 (2013.01); H04L 63/1466 (2013.01)] | 18 Claims |

|
1. A computer system comprising:
a memory; and
at least one processor coupled to the memory and configured to:
identify a first domain name associated with a website that served a login form for entering user credentials to a web browser;
identify a one-time password (OTP) entry request served from the website in response to transmitting the user credentials to the website;
identify a second domain name associated with an OTP server that provided an OTP corresponding to the OTP entry request;
determine that the first domain name differs from the second domain name; and
perform a security action in response to the determination.
|