No real company will ask you to read a verification code back to a human being. Not by phone, not by text, not in a chat window. So the rule is short: never share your OTP with anyone who reaches out to you. If someone does ask, it's a scam. Every time, no exceptions. Learn that one line and you've blocked most one-time-password fraud. The rest of this piece covers the verification-code scams it defeats.
We run a service built on SMS codes, so we watch them get abused daily. The schemes rhyme, and once you spot the pattern it stops working on you.
Why a six-digit code is worth stealing
A one-time password exists to prove that whoever's holding the phone controls the account. It also turns those six digits into a temporary key. If an attacker already has your phone number or email and can talk you into reading the code aloud, plenty of services will let them log in or reset your access. Our explainer on how OTP codes work covers the mechanics. The short version: the code is safe only while it sits on your screen.
Estimates put global SMS fraud losses in the tens of billions of dollars a year. Code-request scams stay a favorite because they involve no hacking at all, just a believable story and a cooperative victim.
How a code-request scam plays out
Nearly every version hits the same three beats.
- The setup. The scammer already has your number and triggers a genuine code to be sent to you, from a service you use or one they're registering in your name.
- The story. They reach out with a reason to need it. "I typed your number by accident." A parcel that "won't release without a code." A job onboarding step. A promising new match on a dating app.
- The ask. They request the code, friendly and urgent at once. The second you read it out, they finish a login or a password reset on their end.
The signature never changes: urgency, a stranger, and a demand for a number that hit your phone moments ago.
The scripts you'll actually meet
- The wrong-number code. "So sorry, I entered your digits by mistake, can you forward the code you just got?" This is the workhorse.
- The courier. A fake delivery outfit claims a code is required to release your package.
- The employer. A suspiciously generous job offer folds "read us this code" into onboarding.
- The romance angle. A brand-new match wants you to "prove you're real" by handing over a code.
Same goal, four masks.
Red flags, at a glance
Three signals in one message or call, and you stop:
- It pushes you to move fast.
- It comes from someone you don't genuinely know.
- It wants a code, PIN, or number that just landed on your phone.
Being polite about it changes nothing. A fake OTP request can be perfectly courteous. Real companies reach you inside the app or your account. They don't call to have a code read back.
When an OTP arrives out of nowhere
An unexpected OTP message is itself information. A lone stray code might be a genuine wrong number. Several inside a few minutes is a different story: somebody is leaning on one of your accounts. Don't tap approve. Don't forward anything. Change the password on whatever account those codes belong to. And if they're for a service you've never used, read it as someone trying to open an account in your name.
Where temporary numbers fit, and where they don't
Grabbing a public number for a throwaway sign-up is a sensible privacy move, and it's what SMSS.net is for. It's the mirror image of the scam above. On a public inbox, anyone can read the code, so you use it only for low-stakes accounts you don't mind exposing. Your real accounts work the other way around: the code is a secret you keep, and no story, however smooth, is worth breaking that for.
So if someone asked for my code and I hadn't started the request myself, they'd get silence. You can use a temporary number for the accounts where a shared code costs you nothing. For everything that matters, the digits stay where they landed.
Frequently asked questions
Someone asked me to read them a code they "sent by mistake." What do I do?
Nothing. Don't share it, don't reply. A code sent to your number belongs to you and nobody else, and anyone pushing you to read it out is trying to hijack an account. Ignore them. If the code showed up next to a login alert, go change that account's password.
Why am I getting codes I did not request?
Almost always because someone is trying to log into or register an account using your number. One stray code might be a real wrong number. Several in a short window means an account of yours is under active attack. Don't approve them, and don't forward them.
Can a scammer do anything with just my OTP?
Often, yes. Plenty of accounts treat a valid one-time code as proof of identity, so your code plus your phone number or email can be enough to log in or reset access. So keep it on your screen and give it to no one.
Are these scams common?
Very. Industry estimates put global SMS-related fraud losses in the tens of billions of dollars, and code-request scams rank among the most common tactics precisely because they skip the malware and lean on persuasion instead.
Try it yourself
Receive an SMS code on a free public number in seconds — no sign-up required.
