FREE TOOL · OTP INTERCEPTION CHECKER

Did You Just Get Sent a Code You Didn't Ask For?

One-time passcodes (OTPs) are meant to protect you — but scammers have gotten good at tricking people into handing them over. This is different from setting up 2FA: this is about recognizing when someone is trying to steal a code you already have.

Tick anything that applies right now
Tick anything above that applies
Your risk level will appear here

How this scam actually works

The attacker already has your username and password — usually from a data breach or phishing page — and is trying to log into your real account right now. When your account sends you a genuine OTP to verify the login, the attacker contacts you (often within seconds) pretending to be "support" or "fraud prevention," and asks you to read the code back "to confirm it's really you." If you do, they use it to complete their own login, not yours.

How this is different from your 2FA Setup Walkthrough

That tool helps you turn on two-factor authentication in the first place. This one is about recognizing the moment someone is trying to steal a code from you after 2FA is already working — the two are complementary, not the same thing.

THE ONE RULE THAT MATTERS

Never read a one-time code out loud to anyone who contacts you — even if they already seem to know your name, bank, or account details. A genuine company will never ask you to "confirm" a code sent to your own phone.

Why You Got a Code You Never Requested

An unexpected one-time passcode usually means one of three things: someone typed your number into a login page by mistake, a scammer triggered a “forgot password” flow on a site where your email is registered — or someone is actively trying to break into an account of yours right now. None of these require any action beyond awareness.

The Scam That Relies on Your Help

The dangerous variant is the follow-up call: a “bank employee” or “company technician” phones to say a code was sent by mistake and asks you to read it back to cancel it. That code is the key to your account, and reading it aloud hands it over. No legitimate organisation will ever ask you to share a one-time code. Hang up — then change the account’s password if you are worried.

Your Two-Minute Response Plan

Why one-time codes are being targeted

Two-factor authentication worked. It worked well enough that attackers stopped trying to defeat it technically and started attacking the one component that was never upgraded: the person reading the code.

A one-time code is a shared secret with a short life. Anyone holding it in that window can use it. It does not matter whether it arrived by text, was generated by an app, or was read out by an automated call. If you tell somebody the code, you have handed them the second factor. Everything below follows from that.

The four ways codes get taken

1. The callback scam

Somebody phones claiming to be your bank, a delivery firm, or a marketplace. They say they are sending a verification code to confirm your identity, and ask you to read it back. In reality they have just triggered a password reset or a login on your account, and the code confirms it for them.

The rule is absolute: nobody legitimate will ever ask you for a code. Not your bank, not the police, not a support agent, not a courier. The message containing the code almost always says so itself. If somebody asks, they are attacking you, regardless of how professional they sound or what number appears on your screen.

2. Real-time phishing pages

You are sent to a convincing copy of a login page. You enter your username and password, and it asks for your code. As you type, the page passes everything through to the real site instantly. The site accepts the login, and the attacker is in. This is why authenticator apps, while much better than text messages, are not phishing-proof — the code is still something you can be tricked into typing.

Passkeys and hardware security keys defeat this completely, because they are bound to the real website's address and simply will not respond to a copy.

3. SIM swapping

An attacker convinces your mobile provider to transfer your number to a SIM they control, usually with personal details gathered from breaches and social media, sometimes with the help of a bribed employee. Your phone loses signal and their phone starts receiving your codes.

Ask your provider to put a port-out PIN or account lock on your number. Then move your important accounts off text-message codes to an authenticator app or passkeys, which are tied to a device rather than a phone number.

4. Approval fatigue

With push-notification two-factor, an attacker who already has your password fires approval prompts repeatedly, often in the middle of the night, until somebody taps approve to make it stop. Deny every prompt you did not trigger, and treat any unrequested prompt as proof that your password is already compromised.

Signs your codes are being targeted

An unrequested code is not a glitch. It is an alarm. Change that password immediately.

Making yourself a harder target

  1. Move to passkeys wherever they are offered. Nothing is typed, so nothing can be relayed.
  2. Use an authenticator app rather than text messages where passkeys are not available.
  3. Add a port-out PIN with your mobile provider.
  4. Save your backup codes somewhere you can reach without your phone.
  5. Remove your phone number as a recovery method on accounts that offer alternatives.
  6. Never read a code to anyone, in any circumstances, for any reason.

Frequently asked questions

Will my bank ever ask me to read out a code?

No. No legitimate organisation asks for a one-time code, ever. Anybody who does is attempting to take over your account, no matter how convincing they sound or what number shows on your caller display.

I keep getting codes I did not request. What does it mean?

Somebody has your password and is trying to complete the second step. Change that password immediately, from a device you trust, and change it anywhere else you used it.

Are authenticator apps safe from this?

Much safer than text messages, because the code never travels over the mobile network and cannot be intercepted by a SIM swap. They can still be phished in real time, which is why passkeys are stronger again.

What is a SIM swap and how do I prevent it?

An attacker moves your phone number onto a SIM they control by deceiving your mobile provider. Ask your provider for a port-out PIN or account lock, and move important accounts away from text-message codes.

My phone suddenly lost signal. Should I worry?

Usually it is an ordinary network problem. If it happens with no explanation in an area with good coverage, and especially alongside unexpected account emails, contact your mobile provider promptly to check that your number has not been transferred.