The controller handles incoming requests and puts any data the client needs into a component called a model. When the controller's work is done, the model is passed to a view component for rendering.
Hackers don't need to break your MFA if they can just trick your team into sending money, which is why your "unauthorized ...