HomeGuides › Someone Asked for Your Verification Code

Someone Asked for Your Verification Code? It's a Scam

By The CODASMS TeamUpdated July 31, 2026
Quick answer: If anyone — a "support agent," a buyer, a match, even a friend's account — asks you to read out a verification code, stop. A one-time code is meant only for you to enter yourself. No legitimate company or person ever needs it. Sharing it hands them your account.
#1
SMS phishing is now the leading mobile attack channel
Independent 2025–26 mobile-threat reporting
14×
Jump in AI-assisted phishing in a single month, late 2025
Independent phishing-trend research
0
Legitimate reasons to read your code to anyone
CODASMS

The one rule that beats this scam

A verification code — the short number an app texts you to confirm it's really you — is a password that lasts a few minutes. It is meant to travel from the app, to your phone, to the login box you are typing into. That's the whole journey. The moment a code leaves that path and goes to another human being, it stops protecting you and starts protecting them.

So the rule is simple and absolute: never tell anyone a verification code. Not a caller who says they're from your bank, not a buyer on a marketplace, not "support," not someone messaging from a friend's hacked account. Real companies never ask for it, because they never need it.

Why a stranger wants your code

They already have half of your login. Maybe your email and password leaked in an old data breach, or they're registering something in your name. The verification code is the last lock. They can trigger that code to your phone at will — by clicking "forgot password" or "log in" on the real service — but they can't see it. So they manufacture a reason for you to read it back.

Common scripts you'll hear or read:

Anatomy of a verification-code scam ANATOMY OF A CODE SCAM 1 They have yourpassword from a breach ora guess 2 They triggerthe code the real app textsit to your phone 3 They ask youto read it posing as support,a buyer, a friend 4 Account gone the code was thelast lock — stopat step 3
The takeover only works if you complete step 3. Refuse to read the code and the chain breaks — the attacker is left holding a password that can't get past verification.

How to spot it in the moment

The pressure is the point. Scammers manufacture urgency so you act before you think. Watch for these tells:

The safe move every time: hang up or stop replying, then open the app or website yourself and log in directly. If something is genuinely wrong with your account, you'll see it there — and you'll never have handed a code to a stranger.

If you already shared a code

Don't panic, but move quickly — minutes matter:

  1. Open the real app or website (not a link they sent) and change your password immediately.
  2. Sign out of all devices / active sessions if the account offers it.
  3. Check recent logins and account activity, and mark anything you don't recognise.
  4. Turn on stronger 2FA — an authenticator app or a passkey is harder to phish than SMS.
  5. For banks or payment apps, call the number printed on your card and tell them what happened.

If you want a deeper walk-through of authenticator apps and passkeys versus SMS, see our guide on OTP vs authenticator app vs passkey.

Lower how often you're targeted

You can't stop scammers from existing, but you can shrink your exposure. Every time you hand your real phone number to a random signup, it can end up in a breach or a broker list — and breached numbers are exactly what these attacks are built on. Using a separate number for signups and verifications keeps your personal line out of that churn, so you get fewer of these attempts in the first place. Here's how a personal number ends up spammed after signups, and why a dedicated verification number helps.

Just remember: a separate number changes how often you're targeted, not the rule. Whatever number a code lands on, it's still yours alone — never read it to anyone.

Keep signups off your personal number

Verify with a separate number so your real line stays out of breaches and spam lists. 180+ countries, 700+ services, pay only when the code arrives.

Get a verification number

Frequently asked questions

Should I ever give someone my verification code?

No. A one-time verification code is meant only for you to type into the app you are logging into. No real company, support agent, buyer, or friend ever needs you to read it to them. If anyone asks, it is a scam.

Why would a stranger want my code?

Because they already have your password or are creating an account in your name, and the code is the last thing standing between them and your account. They trigger the code to your phone, then trick you into reading it back so they can complete the login or takeover.

I already shared a code. What do I do?

Act fast: open the real app, change your password, sign out all devices, and review recent logins. Turn on an authenticator app or passkey if the account supports it. If it is a bank or payment account, contact them directly using the number on your card.

How can I tell a fake support message from a real one?

Real companies contact you inside their app and never ask for a one-time code, password, or PIN. Pressure, urgency, and a request to read a code out loud are the tells. When in doubt, stop and log in to the service directly instead of replying.

Does a verification number protect me from this scam?

Using a separate number for signups keeps your real number out of breaches and away from spam, which reduces how often you are targeted. But the golden rule still holds: never read a code to anyone, on any number.

Related guidesGetting Verification Codes You Didn't Request? What It Means →Is SMS OTP Secure? →OTP vs Authenticator App vs Passkey →Why Your Personal Number Gets Spammed After Signups →What Is an SMS OTP and How Does It Work? →Get a number →
Get your numberPay only when the code arrives
Get a number