A little knowledge. More peace of mind.Independent ideas · September 2026The newsletter ↗
Clear, practical guidance to help protect your home, your family and your digital life.Fly Far
Scam Watch · Practical guide

One-time codes are not something support should ask you to forward

A one-time code can authorise access or a transaction. Someone asking you to read it aloud may be trying to complete a sign-in that you did not start.

A staged cybersecurity portrait
A staged cybersecurity portrait. Photo via Pexels · License & credits. Illustrative stock photography.

Pause the interaction

If an unexpected caller or message asks for a code, stop and contact the organisation through a known route. Do not use a phone number supplied in the suspicious conversation. Read the code message itself; it may state what action is being approved.

Check your account independently

Open the genuine app or website and review activity. If you shared a code, follow the provider's account-recovery guidance promptly. For a payment-related code, contact the financial provider through the number on your card or an established app.

Make a household rule

Agree that nobody needs to prove they are helpful by sharing a sign-in code with an unsolicited contact. Keep the rule short enough to remember during a stressful call. Do not shame someone who has already done it; timely reporting is more useful than blame. This is general fraud-prevention guidance. The exact response depends on the service and action involved, so use official support for the affected account.

Sources & further reading

Source material and official guidance. Original practical suggestions are editorial content, not statements from the organisations below. Checked September 14, 2026.

Have a correction or a question about this article? Contact the editorial team. Read our editorial policy and disclaimer.