Someone Asked for Your Verification Code? It's a Scam
The one rule that beats this scam
A verification code — the short number an app texts you to confirm it's really you — is a password that lasts a few minutes. It is meant to travel from the app, to your phone, to the login box you are typing into. That's the whole journey. The moment a code leaves that path and goes to another human being, it stops protecting you and starts protecting them.
So the rule is simple and absolute: never tell anyone a verification code. Not a caller who says they're from your bank, not a buyer on a marketplace, not "support," not someone messaging from a friend's hacked account. Real companies never ask for it, because they never need it.
Why a stranger wants your code
They already have half of your login. Maybe your email and password leaked in an old data breach, or they're registering something in your name. The verification code is the last lock. They can trigger that code to your phone at will — by clicking "forgot password" or "log in" on the real service — but they can't see it. So they manufacture a reason for you to read it back.
Common scripts you'll hear or read:
- "We detected fraud on your account — read me the code to verify your identity." Banks and platforms never confirm identity by asking for a code they just sent you.
- "I'm sending a code to make sure you're a real seller/buyer." A classic marketplace takeover — the "buyer" is registering your number to a new account.
- "Hey, I got locked out and my reset code went to your number by mistake — can you send it?" A hijacked friend's account fishing for your code.
- "To claim your prize/refund, confirm the 6-digit code." There is no prize.
How to spot it in the moment
The pressure is the point. Scammers manufacture urgency so you act before you think. Watch for these tells:
- They contacted you — an unexpected call, text, or DM, not something you started.
- They ask for a code, password, or PIN. No legitimate agent ever will.
- There's a deadline — "your account will be closed in 10 minutes."
- They discourage you from checking — "don't hang up," "don't open the app, just read me the number."
If you already shared a code
Don't panic, but move quickly — minutes matter:
- Open the real app or website (not a link they sent) and change your password immediately.
- Sign out of all devices / active sessions if the account offers it.
- Check recent logins and account activity, and mark anything you don't recognise.
- Turn on stronger 2FA — an authenticator app or a passkey is harder to phish than SMS.
- For banks or payment apps, call the number printed on your card and tell them what happened.
If you want a deeper walk-through of authenticator apps and passkeys versus SMS, see our guide on OTP vs authenticator app vs passkey.
Lower how often you're targeted
You can't stop scammers from existing, but you can shrink your exposure. Every time you hand your real phone number to a random signup, it can end up in a breach or a broker list — and breached numbers are exactly what these attacks are built on. Using a separate number for signups and verifications keeps your personal line out of that churn, so you get fewer of these attempts in the first place. Here's how a personal number ends up spammed after signups, and why a dedicated verification number helps.
Just remember: a separate number changes how often you're targeted, not the rule. Whatever number a code lands on, it's still yours alone — never read it to anyone.
Keep signups off your personal number
Verify with a separate number so your real line stays out of breaches and spam lists. 180+ countries, 700+ services, pay only when the code arrives.
Get a verification numberFrequently asked questions
Should I ever give someone my verification code?
No. A one-time verification code is meant only for you to type into the app you are logging into. No real company, support agent, buyer, or friend ever needs you to read it to them. If anyone asks, it is a scam.
Why would a stranger want my code?
Because they already have your password or are creating an account in your name, and the code is the last thing standing between them and your account. They trigger the code to your phone, then trick you into reading it back so they can complete the login or takeover.
I already shared a code. What do I do?
Act fast: open the real app, change your password, sign out all devices, and review recent logins. Turn on an authenticator app or passkey if the account supports it. If it is a bank or payment account, contact them directly using the number on your card.
How can I tell a fake support message from a real one?
Real companies contact you inside their app and never ask for a one-time code, password, or PIN. Pressure, urgency, and a request to read a code out loud are the tells. When in doubt, stop and log in to the service directly instead of replying.
Does a verification number protect me from this scam?
Using a separate number for signups keeps your real number out of breaches and away from spam, which reduces how often you are targeted. But the golden rule still holds: never read a code to anyone, on any number.