Attackers sent a Retool employee an SMS phishing link impersonating IT, harvested credentials, then phoned the employee using a deepfaked clone of a real colleague's voice to obtain the MFA/OTP code. That let them register their own device on the victim's Okta account and pivot into customer accounts.