Two-factor code theft
Two-factor code theft happens when a scammer tricks you into sharing a one-time code sent by text, email, or an app. These codes act as a second lock on your accounts. If you read one aloud or type it into a fake page, the scammer can log in as you, reset your password, or approve payments in your name.
How this scam works
The scammer usually already has your email, phone number, or password from a data breach or phishing. They start a login or password reset, which makes the real company send you a code. Then they contact you at the same time, pretending to be your bank, a mobile carrier, a tech company, or a buyer on a marketplace, with a reason why you should read the code back.
Common excuses include verifying your identity, stopping a fraud charge, canceling an order, or proving you are a real seller. Some fake login pages ask for the code right after your password. Once the scammer has the code, they move fast to change your password, recovery email, and phone number so you cannot get back in.
What it can look like
EXAMPLE · NOT A REAL MESSAGECall: "This is the fraud department at your bank. We just blocked a suspicious $900 transfer. To confirm you are the account holder, we sent a code to your phone. Please read me that code so we can stop the transfer."
Warning signs
- Someone asks you to read back or forward a code sent to you
- You receive a code you did not request, followed by a call or message
- The text with the code says not to share it, but the caller insists
- A caller claims the code is needed to stop fraud or cancel a charge
- A marketplace buyer wants a code to "verify" you are real
- A login page appears from a link in a message and then asks for your code
How to protect yourself
- Never share a one-time code with anyone who contacts you, even if they seem official.
- Read the full text with any code; it often warns not to share it.
- If a caller claims to be your bank, hang up and call the number on your card.
- Use an authenticator app or security key where offered.
- Use unique, strong passwords so a breach of one site does not unlock others.
If you already responded
- Sign in to the affected account and change your password right away, if you can.
- Check that your recovery email and phone number have not been changed, and sign out other sessions.
- If you cannot get in, use the company's official account recovery process from its help center.
- For a bank account, call the number on the back of your card or statement and report it.
- Report the scam to the FTC, and visit IdentityTheft.gov if your information was misused.
Get step-by-step recovery help →
Where to report it
Common questions
Will my bank ever ask me for a verification code over the phone?
Be very cautious. Many banks say they will never call and ask you to read back a code they sent. If someone calls claiming to be your bank and asks for a code, hang up. Call the number on the back of your card or on your statement to check whether there is a real problem.
Why did I get a verification code I didn't ask for?
Someone may be trying to log in to your account or reset your password, possibly with a password stolen in a data breach. Do not share the code. Change that account's password to a unique one and check its recent activity.
Is two-factor authentication still worth using if codes can be stolen?
Yes. It still blocks many attacks, because a stolen password alone is not enough. The key is never sharing codes. For extra protection, consider an authenticator app or a security key where your account allows it.