My mother received a letter telling her to install an authenticator app to access her pension account. She searched the iPhone App Store for Microsoft Authenticator but accidentally installed a similarly named third-party app instead. The app initially let her sign in to the pension website, then demanded a $5 subscription, so she deleted it without paying.
We changed her pension and email passwords and plan to contact the pension provider to report what happened. The fake app also generated a one-time code that worked on the pension site, so we are unsure whether the old MFA setup is still active. Could the app have accessed her Apple ID, email, passwords, or other data? Should she change her Apple ID password, and what steps should we take to secure the pension account and set up MFA again?
4 Answers
This appears more likely to be a misleading subscription app than an obvious credential-stealing app. iOS apps are sandboxed, so an app generally cannot read unrelated passwords, email, or Apple ID data unless she entered those credentials into it or granted it unusual permissions. Still, changing passwords for accounts used during the setup was sensible. Check the iPhone's subscriptions, remove any unknown configuration profiles or permissions, and confirm that the fake app is gone. If she never entered her Apple ID password into the app, changing it is mainly a precaution rather than an absolute necessity.
A fake authenticator can still generate a valid code if it received the account's setup secret when MFA was enrolled. That does not necessarily mean it can access every account on the phone, but anyone who obtained that secret could potentially generate future codes for that pension account. Re-enrolling MFA with the legitimate app is the safest fix. Also sign out other sessions if the pension provider supports that feature.
Review what happened during installation: check whether she typed her Apple ID, email, pension password, or any other credentials into the app or a web page it opened. If so, change those passwords from a trusted device and make sure each account has its own password and MFA. Also inspect Apple subscriptions and purchase history so the app did not start a recurring charge. A factory reset usually is not needed for a normal App Store app unless there are other signs of compromise.
The important step is to have the pension provider revoke the old authenticator enrollment and issue a new setup. Changing the website password does not always invalidate the secret used to generate time-based one-time codes. Ask them to remove all existing MFA devices or sessions, enroll the genuine authenticator app again, and verify that no recovery email, phone number, payment details, or account information was changed.
After changing the password, the site stopped offering the QR code and codes from the genuine app do not work, so I am contacting the pension provider to reset the MFA enrollment.

The App Store listing and user reviews may help confirm whether the main issue was an unwanted subscription, but reviews are not proof that the app was harmless. Treat the pension account as potentially exposed until the provider confirms otherwise.