What is changing now
The current pattern.
Verification-code scams combine impersonation with a real security message. The code genuinely comes from the account provider, but it was triggered by the scammer’s login or recovery attempt. Variants use bank fraud stories, marketplace verification, support calls, repeated push notifications and phone-number registration services.
How it works
Confidence first, then pressure.
The attacker may already know a password from phishing, reuse or a data breach. They start a login and create an authentic code or approval prompt. At nearly the same time, an impersonator contacts the account holder and supplies a story explaining why the code must be shared.
Another variant starts an account-recovery or phone-number registration flow. The victim is told that reading back the code proves identity or confirms a listing, while the code actually authorises an account or service controlled by the attacker.
The security message may say not to share the code, identify the attempted device or describe the action being approved. Those details are more reliable than the caller’s interpretation. A code should be entered only into the service the user intentionally opened for their own login.
Worked example
A realistic pattern, separated into evidence.
This composite example is educational. It does not describe a real person or reproduce a live malicious message.
A fraud caller explains a real banking code
- 01The opening
A caller claims to be investigating a suspicious card payment. During the call, a genuine text from the bank arrives with a six-digit code, making the call appear connected to the real account.
- 02The escalation
The caller says the code cancels the transaction and warns that delay will make the customer responsible. The text itself says the code approves a new device and should not be shared.
- 03The decision point
The bank sent a real message because someone initiated a real account action. That does not make the caller genuine; it shows that the caller may be the person attempting the action.
Warning signs
Reasons to stop and verify.
- A caller or message asks you to read back a one-time login code
- An approval prompt arrives for a login or device you did not initiate
- Repeated notifications pressure you to approve one just to make them stop
- A marketplace contact says a code will prove you are a real person
- The caller’s explanation conflicts with the action described in the security message
- A request to change recovery email, phone, passkey or trusted-device settings
Independent verification
Test the request without using its evidence.
These checks deliberately move the decision away from the person, link, number or account that introduced the request.
- 01
Read the security message literally
Identify the action, account and device described. Do not replace the provider’s warning with the caller’s explanation of what the code supposedly does.
- 02
Reject actions you did not initiate
Do not share a code or approve a prompt unless you personally started that exact login on a service you opened independently.
- 03
Open the real account
Use the official app or a saved address to review sessions, security alerts, recovery details and recent activity.
- 04
Move to stronger authentication
Where available, prefer passkeys or phishing-resistant security keys. They reduce reliance on shareable codes, but account-recovery details still need protection.
Safer response
Move the decision outside the contact.
- 01
Stop the conversation
End contact with anyone asking for a code, approval or recovery change, regardless of the identity they claim.
- 02
Secure the primary email first
Email often controls recovery for other accounts. Review its sessions, forwarding rules, passwords and strong authentication.
- 03
Revoke unknown access
Remove unfamiliar devices, sessions, apps, recovery methods and passkeys through the real provider.
- 04
Contact providers directly
Use the official recovery and support process if access or account settings have changed.
If you already acted
Protect access and contact the real provider.
- Use the provider’s official recovery flow immediately and change the password from a trusted device.
- Sign out unfamiliar sessions and remove unknown recovery methods, devices, forwarding rules and app access.
- Secure any email or phone account that can reset the affected service.
- Contact the bank or payment provider if the account could move money or stored payment details.
- Warn contacts if messages may have been sent from the compromised account.
Sources
Official guidance used for this article.
Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.