One-time passcode
A short code sent by text or generated by an app to confirm a login or payment. Reading one out to a caller hands over the account.
The codes exist precisely so that knowing a password is not enough. Handing one to a caller removes the only protection that was still working.
The pretexts are consistent: the caller says the code proves you are you, or that it will cancel a fraudulent transaction, or that it is needed to verify a refund. It never does any of those things. A genuine bank will never ask you to read one out, and a genuine push notification will describe an action you started yourself. If you did not initiate it, decline it — and if you approved one by mistake, call your bank straight away.
Where it shows up
- Bank impersonation and the safe account — A call from your bank's real number, telling you your money is at risk and must be moved somewhere safe.
- Phishing and smishing — A small, cheap problem and a link that fixes it — on a screen where you cannot see where the link goes.
- SIM swap — Someone convinces your mobile carrier to move your number to their SIM, and every code you rely on starts arriving on their phone.