I was filling out a rental application on on-site.com and a modal popped up telling me I had been texted a link and had 5 minutes to resend the link. I got a text from 32858 and it was of the form https://api.equifax.com/business/secure-mfa/v2/authentications/verification-tokens/<long hexstring>/verify. I clicked on it and it took me to a page that just had the text, "Authentication completed. Return to your application," or something like that. I don't remember what the domain was.
I couldn't find anything online about this, so I'm wondering, is this legit? Or is this somehow an elaborate ploy to steal my identity? What's also weird is that the website didn't change after I clicked on the link, but at some point I saw a back button on the page which closed the modal, and now I'm wondering if that button was there the whole time. Also, if I tap on the link again, I get redirected to secureauth.io/expired, but I can find no information about that domain online. My co-applicant never had the modal pop up and never got a text.
It was subsequently acquired by Realpage. (also a legitimate company) Surprised to hear anything is still running at the On-Site domain name, but checking the WHOIS shows that the domain is pointing at RealPage servers, so it seemingly hasn’t been squatted on.
If it was legitimately the On-Site.com domain I think you’re fine. More likely just a kludgy bug.
If you have a link to the form, I can pass it along to the On-Site folks to verify.