My mother received a letter saying she needed an authenticator app to access her pension website. She searched the iPhone App Store for Microsoft Authenticator but accidentally installed a similarly named third-party app instead. It let her sign in to the pension site and generated a working one-time code, but then asked for a $5 subscription, so she stopped and deleted it. We changed her pension and email passwords, but we have not yet confirmed whether the old MFA enrollment was revoked or set up again. Could the app have accessed her Apple ID, email, pension account, or other data? Should she change her Apple ID password, reset other passwords, or factory-reset the phone?
3 Answers
The app may simply be a legitimate third-party authenticator wrapped in misleading branding and an aggressive subscription model. On iOS, an app generally cannot access other apps' passwords or account data unless she entered those details into it, granted sensitive permissions, or approved a login request. Still, changing passwords for accounts used on the phone is reasonable, especially the pension account and email, and the app should be removed. Check the Apple ID purchase and subscription sections to make sure no trial or recurring charge was activated.
There is no clear evidence from this alone that the Apple ID or every account on the phone was compromised, and a factory reset is probably unnecessary if she only installed the app, did not enter unrelated passwords, and did not grant unusual permissions. Review the app's permissions, delete any unknown configuration profiles, check for unfamiliar devices signed in to the Apple ID, and monitor email, pension activity, and card statements. Change the Apple ID password if it was entered into the app, reused elsewhere, or if you want extra peace of mind; otherwise, enable two-factor authentication and verify trusted devices.
The most important next step is contacting the pension provider and asking them to remove the old authenticator enrollment and issue a new setup process or QR code. Changing the password alone may not invalidate an already enrolled authenticator. Once they reset MFA, enroll the official app or another authenticator they explicitly support and verify that old sessions and recovery methods have been revoked.
After the password change, the site no longer offered a QR code, so the provider will need to help reset the MFA enrollment.

The main concern was whether installing it briefly could have exposed her Apple ID or email even though she did not knowingly enter those passwords into the app.