GuideHQ

I read out a one-time passcode — what happens now?

What the code was actually authorising, why the message you were sent already told you, and the order to work in during the next thirty minutes.

Difficulty
beginner
Time
30 min
Read
3 min
Safety
warning

Short answer

Work out what it authorised — the text itself usually says, and it is worth re-reading. Then ring your bank immediately if it was financial, change the password on that account from a device you trust, sign out all other sessions, and check for new payees, new devices and changed contact details. Codes expire quickly, so speed genuinely helps.

One-time codes are effective, which is why criminals need you to read them out. The request always comes with a reason — proving you are a real seller, confirming a refund, verifying an account, releasing a delivery — and none of those reasons exist. Nothing legitimate ever requires you to tell somebody a code sent to you.

Safety

A one-time passcode is the last barrier on an account, and giving one away hands over whatever it was protecting — usually a payment, a new payee, a device registration or an account takeover. Act within minutes rather than hours. If the code was for banking, ring the bank now on 159 or the number on your card.

Step by step

  1. Re-read the message that contained the code.Almost all of them say what they authorise: a payment of a stated amount, a new payee, a login from a new device, a password reset, or registering an account with your number. That tells you exactly what to act on.
  2. If it was banking, ring the bank now.159, or the number on the back of your card. Tell them a code was disclosed and what it appeared to authorise. Ask them to block any pending payment, remove any new payee and check for new device registrations.
  3. If it was an account login, change that password immediately.From a device you trust, not the one you were being talked through. Then use "sign out of all sessions" in the security settings, because a password change alone does not always end an existing session.
  4. Check for the changes attackers make next.New recovery email addresses and phone numbers, mail forwarding rules and filters, new trusted devices, new payees, changed delivery addresses. These are how access is kept after the password changes.
  5. If it registered a messaging account, reclaim it.Re-register the app with your own number to take it back, and turn on the app's two-step verification PIN so it cannot be repeated. Warn your contacts, because your account will already be messaging them asking for money.
  6. Turn on a stronger second factor.Where the account offers it, replace SMS codes with an authenticator app or a passkey. Codes that arrive by text are the ones that can be talked out of people.
  7. Watch the accounts for a few weeks.Statements, sign-in activity, and any messages about applications you did not make. Disclosure of a code is often one step in a longer attempt.
  8. Report it.Action Fraud, or Police Scotland on 101 in Scotland. Forward the scam text to 7726 if it came by message.

Tips

  • The code message itself almost always contains a warning line saying nobody will ever ask for it. That line is there because this is the single most effective request a criminal makes.
  • A caller who says the code is "to verify you are the account holder" is describing the opposite of what is happening — the code proves to the service that whoever holds it is you.
  • If you were talked through it while on a call, expect the caller to ring back with a new story. Do not answer; ring the organisation yourself.

Common mistakes

  • Assuming the code expired and no harm was done — They are used within seconds. Check the account rather than assuming.
  • Only changing the password — Sessions, recovery details, forwarding rules and registered devices all survive a password change. All four need checking.
  • Reading out a second code to "cancel" the first — That is a standard follow-up and it authorises something else. There is no code that cancels a code.

Questions people ask

What could they do with a single code?

Whatever the code authorised — approve a payment, add a payee, sign in from their device, reset a password, or register a messaging account to your number. The message text tells you which.

Does this stop me being reimbursed?

Not automatically. Sharing a code is a factor a bank will weigh, but the standard is gross negligence rather than any mistake, and being deceived by a convincing impersonation is not the same thing. Report immediately and make the claim.

How do I stop this happening again?

Replace SMS codes with an authenticator app or passkeys where offered, and adopt one absolute rule: never tell anyone a code, whoever they say they are and whatever reason they give.

Written and maintained by the GuideHQ editorial team. More in Technology.