A good case for 2-factor authorization on your email as well as your bitcoin accounts, as well as a text/email alert system for activity on your account. I'm a little surprised the heads of the company didn't have text messages being sent to them for any transfers over a certain amount.
In fact, this is an excellent case for multi-factor authentication and multi-signature, combined, to be implemented.
Example below as to how such could've been used to thwart the successful ~$1.8M phishing attempts if were in place:
MFA:
Password: liver1212
Cat's name: TabbY
School mascot: Tiger
Mother's maiden name: Smith
Dog's name: Spot
Last four digits of your SSN: 1234
MS:
Sign if you approve this 1,000 BTC transfer: Tony
Sign if you approve this 1,000 BTC transfer: Stephen
Sign if you approve this 1,000 BTC transfer: Bryan
Sign if you approve this 1,000 BTC transfer: Alice (in laundry)
Sign if you approve this 1,000 BTC transfer: Bob (the janitor)
Due to the size of the above transaction, please wait at least
one hour before playing again.
MFA:
Password: liver1212
Cat's name: TabbY
School mascot: Tiger
Mother's maiden name: Smith
Dog's name: Spot
Last four digits of your SSN: 1234
MS:
Sign if you approve this 1,000 BTC transfer: Tony
Sign if you approve this 1,000 BTC transfer: Stephen
Sign if you approve this 1,000 BTC transfer: Bryan
Sign if you approve this 1,000 BTC transfer: Alice (in laundry)
Sign if you approve this 1,000 BTC transfer: Bob (the janitor)
Due to the size of the last two transactions, please wait an additional at-least
twelve hours before playing again.
MFA:
Password: liver1212
Cat's name: TabbY
School mascot: Tiger
Mother's maiden name: Smith
Dog's name: Spot
Last four digits of your SSN: 1234
MS:
Sign if you approve this 3,000 BTC transfer: Tony
Sign if you approve this 3,000 BTC transfer: Stephen
Sign if you approve this 3,000 BTC transfer: Bryan
Sign if you approve this 1,000 BTC transfer: Alice (in laundry)
Sign if you approve this 1,000 BTC transfer: Bob (the janitor)
Due to having the combined MFA and MS in place, a phishing attempt was almost halted in its tracks. Thanks for playing. Enjoy the rest of your Break-away Friday.
I like it phin. Perfect way to avoid a hack. Other variations exist but this is pretty comprehensive other than an actual token key each person could have to sign/verify they are who they are in the confirmation process.