ScamsPhishingThe verification-code scam: why no one legitimate ever asks for the code you just got
High

The verification-code scam: why no one legitimate ever asks for the code you just got

A text arrives with a six-digit code you didn't request, then someone calls — your "bank," a "buyer," tech "support" — and asks you to read it back. That code is the key to your account, and handing it over is exactly how takeovers happen. Here is the one rule that stops it.

Sources checked:FTCFBI

It often starts with a text you weren’t expecting: a six-digit verification code. A moment later, someone reaches out — a caller from your “bank,” a “buyer” for the item you listed, a “support” agent — with a friendly, urgent reason they need you to read that code back. Hand it over and, in many cases, your account is gone within minutes.

How the scam works

A verification code (a one-time passcode, or OTP) is a second key to your account — the thing that proves it’s really you logging in. Scammers want that key, and they’ve learned it’s easier to ask for it than to steal it.

  • The setup. Often the criminal already has your password — from a breach or an earlier phishing page — and just needs the code your bank or email texts you to complete the login. Sometimes they trigger that text themselves, so it lands on your phone at the exact moment they call.
  • The pretext. They “pretend to be someone you can trust,” the FTC notes, and “say they’ve discovered a problem with one of your accounts — or that someone’s using your identity.” They may know real details about you and sound genuinely helpful — “offering to help you set things right … and then asking for your verification code.”
  • The handover. You read the code aloud or type it into a chat. That’s all it takes. As the FTC puts it, “if you share that code, the scammer can use it to prove they’re you,” and then “they can log into your account and transfer all the money out.”

The FBI describes the same pattern at scale: criminals “manipulate account owners into giving away their login credentials, including multi-factor authentication (MFA) codes or One-Time Passcodes (OTP), by impersonating financial institution employees, customer support, or technical support personnel.” In 2025, the FBI’s IC3 tied account-takeover fraud to more than 5,100 complaints and over $262 million in reported losses.

The one rule that stops it

There is a single sentence that defeats every version of this scam, and the FTC states it flatly: “Anyone who asks you for your account verification code is a scammer. No caller — especially someone from your bank’s fraud department — will ever ask for the verification code. That’s always a scam.”

That’s the whole defense. It doesn’t matter how the request is dressed up — bank security, a marketplace buyer “confirming you’re real,” a delivery service, tech support. Legitimate companies generate those codes for you to enter into their app or site. They never need you to relay one to a person.

How to spot it

The cluster to recognize: a code you didn’t request + someone contacting you who wants that code + a sympathetic, urgent reason. A code arriving on its own can mean someone is already trying your password. A person asking for it means a takeover attempt is in progress right now.

What to do instead

The move is Go Direct: never give a code to anyone who contacts you, and if you’re worried something is wrong, reach the company yourself — through its official app or the number printed on your card — rather than trusting the call or text that came to you. If someone pressures you for a code, hang up; the FTC’s advice is to “don’t engage. Hang up. Block their number,” then report it at ReportFraud.ftc.gov.

To make your accounts harder to take over in the first place, set up stronger verification ahead of time — an authenticator app or a security key beats SMS codes. That’s part of Lock the Front Door. This scam also overlaps with the bank “fraud department” call, and with SIM-swap attacks that hijack the codes themselves. For more, see the named defense moves or test your eye on the 60-second quiz.

Warning signs
  • You get a one-time code or verification text you didn't request — then someone contacts you and asks you to read it back.
  • The caller claims to be your bank, a buyer, a delivery service, or "support," and has a sympathetic reason they need the code to "verify" you or "fix" a problem.
  • There is urgency: confirm the code now, or your account will be locked, your money lost, or the deal will fall through.
Defense move — Go Direct
  • A verification code is a key to your account. Never read it aloud, type it into a chat, or send it to anyone — for any reason.
  • No real bank, company, or "fraud department" will ever ask you for a code they just sent you. The request itself is the scam.
  • If a call or text pressures you for a code, hang up. Contact the company yourself through its official app or the number on your card — not the one that contacted you.
  • Protect accounts in advance: use an authenticator app or a security key rather than SMS codes where you can.
Editor's note

This is the scam I most wish everyone’s relatives knew cold, because it’s so clean: the criminal often already has your password, and the only thing standing between them and your account is the code on your screen. They don’t hack the code out of you — they ask, politely, with a good story. So the defense is just as clean, and it never changes no matter who’s calling or how urgent it sounds: the code is yours, you say it to no one. If a caller needs it, that sentence alone tells you they’re not who they say they are.

Frequently asked

Someone said they're from my bank's fraud team and just need the code to verify me. Is that real?

No. The FTC is unambiguous: "Anyone who asks you for your account verification code is a scammer. No caller — especially someone from your bank's fraud department — will ever ask for the verification code. That's always a scam." The fraud-department story is convincing precisely because it explains why they'd "need" the code. Hang up and call the number on your card.

What can someone actually do with one six-digit code?

Take over the account. The FTC explains that the code is how you prove who you are, so "if you share that code, the scammer can use it to prove they're you" — and once in, "they can log into your account and transfer all the money out of your savings or investment accounts." The FBI reports that criminals trick people into giving up these codes by impersonating bank, customer, or tech support, and tied account-takeover fraud to over $262 million in reported losses in 2025 alone.

I got a code I never asked for. What does that mean?

It usually means someone already has your password and is trying to get past the second step — or is about to call and talk you into reading the code to them. Don't share it. If it's for an account you recognize, treat it as a prompt to change that password and check your security settings. An unrequested code is a warning light, not a routine message.

RY
Ryon — Founder & Editor
Consumer-safety advocate · Scamblare

Scamblare researches scams every day so you don't have to. Every article is checked, claim by claim, against primary sources like the FTC and FBI IC3 under our published editorial standard. How we fact-check ›