Account takeover

A one-time code is a key, not proof for a caller.

A caller who already has a password may need only one approval, code or recovery change to take control of an account.

8 minute readPublished 23 August 2026Reviewed 23 August 2026Individuals

What is changing now

The current pattern.

Verification-code scams combine impersonation with a real security message. The code genuinely comes from the account provider, but it was triggered by the scammer’s login or recovery attempt. Variants use bank fraud stories, marketplace verification, support calls, repeated push notifications and phone-number registration services.

How it works

Confidence first, then pressure.

The attacker may already know a password from phishing, reuse or a data breach. They start a login and create an authentic code or approval prompt. At nearly the same time, an impersonator contacts the account holder and supplies a story explaining why the code must be shared.

Another variant starts an account-recovery or phone-number registration flow. The victim is told that reading back the code proves identity or confirms a listing, while the code actually authorises an account or service controlled by the attacker.

The security message may say not to share the code, identify the attempted device or describe the action being approved. Those details are more reliable than the caller’s interpretation. A code should be entered only into the service the user intentionally opened for their own login.

Worked example

A realistic pattern, separated into evidence.

This composite example is educational. It does not describe a real person or reproduce a live malicious message.

Composite scenario

A fraud caller explains a real banking code

  1. 01
    The opening

    A caller claims to be investigating a suspicious card payment. During the call, a genuine text from the bank arrives with a six-digit code, making the call appear connected to the real account.

  2. 02
    The escalation

    The caller says the code cancels the transaction and warns that delay will make the customer responsible. The text itself says the code approves a new device and should not be shared.

  3. 03
    The decision point

    The bank sent a real message because someone initiated a real account action. That does not make the caller genuine; it shows that the caller may be the person attempting the action.

Warning signs

Reasons to stop and verify.

  • A caller or message asks you to read back a one-time login code
  • An approval prompt arrives for a login or device you did not initiate
  • Repeated notifications pressure you to approve one just to make them stop
  • A marketplace contact says a code will prove you are a real person
  • The caller’s explanation conflicts with the action described in the security message
  • A request to change recovery email, phone, passkey or trusted-device settings

Independent verification

Test the request without using its evidence.

These checks deliberately move the decision away from the person, link, number or account that introduced the request.

  1. 01

    Read the security message literally

    Identify the action, account and device described. Do not replace the provider’s warning with the caller’s explanation of what the code supposedly does.

  2. 02

    Reject actions you did not initiate

    Do not share a code or approve a prompt unless you personally started that exact login on a service you opened independently.

  3. 03

    Open the real account

    Use the official app or a saved address to review sessions, security alerts, recovery details and recent activity.

  4. 04

    Move to stronger authentication

    Where available, prefer passkeys or phishing-resistant security keys. They reduce reliance on shareable codes, but account-recovery details still need protection.

Safer response

Move the decision outside the contact.

  1. 01

    Stop the conversation

    End contact with anyone asking for a code, approval or recovery change, regardless of the identity they claim.

  2. 02

    Secure the primary email first

    Email often controls recovery for other accounts. Review its sessions, forwarding rules, passwords and strong authentication.

  3. 03

    Revoke unknown access

    Remove unfamiliar devices, sessions, apps, recovery methods and passkeys through the real provider.

  4. 04

    Contact providers directly

    Use the official recovery and support process if access or account settings have changed.

If you already acted

Protect access and contact the real provider.

  • Use the provider’s official recovery flow immediately and change the password from a trusted device.
  • Sign out unfamiliar sessions and remove unknown recovery methods, devices, forwarding rules and app access.
  • Secure any email or phone account that can reset the affected service.
  • Contact the bank or payment provider if the account could move money or stored payment details.
  • Warn contacts if messages may have been sent from the compromised account.

Sources

Official guidance used for this article.

Stop & Verify summarises these sources for general education. Reporting routes and legal protections vary by location.