"Never share this code": how scammers get you to read out your verification code over the phone

Guide

Back to the blog
L'équipe Envoyer SMS Gratuit17 September 202611 min read
Filed underGuide

"Verification code: 748 219. Do not share this code with anyone, including a customer adviser."

You didn't ask for anything. Yet the text comes from a sender you recognise — the name of your bank, of a marketplace, of a payment service. You read it twice, you shrug. And twenty-five seconds later, the phone rings.

At the other end, a calm voice, the faint hum of a call centre in the background, your name pronounced correctly. "Good morning, security department. We've detected an attempted payment of 847 euros on your account from an unknown device. You've just received a code by text message: that's the cancellation code. Could you read it out to me so I can block the transaction?"

That code cancels nothing. It authorises. And the text message warning you was telling the exact truth — except that you were already inside somebody else's script.

Hands holding a smartphone showing a keyboard and a text message being typed

The one-time code, the last lock before the void

Since the European payment services directive (PSD2) came into force, requiring strong customer authentication, almost every sensitive operation goes through a second factor: a code sent by text message, a notification to approve in the banking app, sometimes a fingerprint.

That code — known as an OTP, one-time password — has become the mandatory choke point of any fraud. A crook who has your username and password, obtained in a data breach or through a fake website, can no longer do anything alone. One thing is missing: the six digits that you alone receive.

Hence a complete reversal of criminal strategy. It is no longer about hacking a system, but about convincing a human being to read six digits out loud. That is infinitely cheaper and, unfortunately, more effective.

The Banque de France and the Observatoire de la sécurité des moyens de paiement note it year after year: fraud "involving manipulation of the victim" is rising while purely technical fraud is receding. The attacker no longer needs to be a computer expert. He needs to be an actor — or to have a robot that plays the part for him.

"OTP bots": when the scam becomes a monthly subscription

This is the real change of the past two years, and it is little known to the general public. The theft of verification codes has been industrialised into turnkey services, sold on private messaging channels for a monthly fee.

The principle is depressingly simple. The crook has your credentials (bought in a batch of stolen data). He logs into your online account, which automatically triggers the sending of the genuine text message by the genuine service. At that very moment, he enters your number into the bot and picks a scenario: "bank", "delivery", "crypto platform", "telecoms operator".

The bot dials your number, plays a synthetic voice — often excellent, in accent-free English, complete with call-centre background noise — and asks you to key in or read out the code you have just received. The moment you do, the code is relayed to the crook in real time, and he enters it before it expires. The whole operation takes less than ninety seconds.

Three details make this setup formidable:

  • The timing is perfect. The legitimate text message and the call arrive in the right order, seconds apart. The brain automatically links the two events.
  • The text message is genuine. It really does come from your bank, from the right sender, with the right formatting. Nothing to detect, no dubious link to hover over: there is no link at all.
  • The displayed number is spoofed. Thanks to spoofing, the call appears to come from the number printed on the back of your bank card.

In other words, every reflex we have been taught for the past ten years — check the link, check the sender, check the number — is neutralised at a stroke.

The five scenarios that come up most often

1. The fake "security" adviser

The classic. A suspicious payment has supposedly been detected and must be cancelled. The code is said to "block", "reject" or "secure". A bank never asks for a code in order to cancel something: cancellation happens on its side, without any input from you.

2. The delivery confirmation

A parcel is supposedly held up, a time slot needs confirming. The code allegedly serves to "validate the address". In reality, it often validates the creation of an account or the enrolment of a bank card in a mobile wallet.

3. The peer-to-peer resale

You're selling an item. The buyer sends you a code "to check you're not a robot" before coming over. It is a sign-up code for a third-party service, tied to your number — which will then be used to set up further frauds in your name.

4. The fake telecoms customer service

You're offered a discount, a goodwill gesture, a plan upgrade. The code requested is in fact the one that authorises the transfer of your line to another SIM card. This variant leads straight to the complete hijacking of your number.

5. The "reactivation" of a frozen account

An email account, a classified-ads platform, a mobile payment service: you're told it has been blocked and you're "helped" to unblock it. The code does indeed unblock something — the crook's access.

Smartphone with a green case lying on a white sheet, messaging keyboard displayed on screen

Why careful people fall for it anyway

We have to drop the idea that these scams only target people who are uncomfortable with technology. The scripts exploit universal cognitive mechanisms that are thoroughly documented.

Urgency suppresses verification. A large sum, an account in danger, a two-minute deadline: the brain switches into reaction mode. Studies on decision-making under stress show a sharp drop in the ability to consider alternative hypotheses.

Consistency reassures more than authenticity does. You receive a text message, then someone calls you about that text message: the two elements confirm each other. This is known as the illusion of corroboration. Yet both come from the same source — the crook simply triggered the first one.

Authority disarms contradiction. A calm voice, professional jargon ("stop payment", "transaction rejection", "level 2"), a familiar number. Interrupting someone who seems to be helping you takes genuine social effort.

The wording of the code is worked around. "Do not share this code with anyone" is presented by the crook as an instruction aimed at other calls: "Of course, you're quite right to be suspicious. That's precisely why I'm the one calling you, from the official number." The doubt is absorbed, turned around, converted into proof of legitimacy.

The single rule that blocks all of it

You can forget the lists of ten tips. One sentence protects you from every one of these scenarios:

A code received by text message is never spoken aloud, never keyed into a phone keypad, never forwarded. It is entered by you and you alone, on a screen, in an app or on a website that you opened yourself.

No exceptions. Not for a bank adviser, not for a police officer, not for a technician, not for a delivery driver, not for a buyer. No legitimate professional needs that code, because no legitimate professional is acting on your behalf inside your account.

An equally important corollary: a code received for no reason is a warning sign, not a mistake. If it arrives when you have done nothing, it means someone already has your credentials and is trying to get in. The right reaction is not to ignore the message, it is to change the password of the service concerned immediately, from the official app.

Taking back control: the practical steps

Hang up, then call back yourself

This is the most effective step, and the hardest to take. You hang up, wait a full minute (some crooks keep the line open), then dial for yourself the number shown on the back of your bank card or in the app. If the incident was real, it will still be there in five minutes.

For people who receive a lot of nuisance calls, a landline phone with call screening — which blocks unregistered numbers or requires callers to announce themselves — removes a good deal of the noise. It's a modest investment for an elderly parent who doesn't dare hang up on a polite caller.

Move away from SMS for authentication where possible

SMS remains the weakest authentication factor: it can be intercepted through line hijacking, read on a locked screen, and is vulnerable to the manipulation described here. Where a service offers it, prefer an authentication app (approval in the banking app, code generator) or, for the most sensitive accounts, a physical FIDO2 security key, which has the merit of displaying nothing that could be read out to a stranger.

Lock down message previews

By default, many phones display the content of text messages on the lock screen. A code visible without unlocking is a code exposed to anyone who glances at the device — on a train, in an open-plan office, in a waiting room. The setting is in the notifications menu: choose "hide content". A privacy filter for smartphone screens usefully complements the measure for those who check their phone on public transport.

Protect the line itself

Since the text message arrives on your SIM card, the SIM card becomes a target. Two precautions: enable the card's PIN code (switched off by default for many users) and ask your operator to lock number porting, an option that prevents the line from being transferred without enhanced verification. Those who like to keep their uses separate will appreciate a dual-SIM phone, letting you reserve a dedicated number for banking services, never given out in classified ads or on forms.

Write the rule down on something physical

It sounds naive, yet it is what works best with vulnerable people. A printed card placed next to the landline with three lines: "I never read out a code. I hang up. I call my bank myself." Several prevention charities hand out this kind of memo. A practical guide to everyday cybersecurity, left on the coffee table, often does more for family vigilance than a long lecture.

Hand holding a smartphone showing a text message conversation, at the wheel of a car in the city

If you did give out the code

There is no shame in it — these scripts are designed by professionals who do this full-time. There is, however, an urgency.

TimeframeAction
ImmediatelyCall your bank's card-blocking service (number on the back of the card) and have the card and online access blocked
Within the hourChange the password of the service concerned and of the linked email account, from another device if possible
Within 24 hoursReport it on the official fraud reporting platform and file a complaint at a police station
Within 13 monthsContest the unauthorised transactions in writing with your bank

A few useful reference points:

  • 3018 (free call and service) supports victims of online abuse; Info Escroqueries on 0 805 805 817 advises on the steps to take.
  • Fraudulent text messages can be reported to 33700, a service shared by French operators.
  • The website cybermalveillance.gouv.fr, the national assistance scheme, offers step-by-step fact sheets and a directory of approved providers.
  • The Code monétaire et financier provides for the reimbursement of unauthorised payment transactions, except in cases of gross negligence by the customer. Gross negligence is assessed case by case: having been the victim of an elaborate manipulation, with the bank's number spoofed, has already been ruled in the customer's favour by the Cour de cassation. Keep everything: screenshots, call times, the number displayed, the content of the text messages.

What this scam tells us about what comes next

The SMS one-time code is living out its final years as a security standard. European banking supervisory authorities are already encouraging migration towards methods that tie authentication to the device and to the transaction itself — an approval in the app that displays the amount and the payee, far harder to divert over the phone.

In the meantime, the vulnerability lies neither in the phone nor in the network: it lies in the conversation. A crook does not steal a code, he obtains it. Which means that a single decision — politely declining, hanging up, calling back yourself — is enough to break an entire attack chain, voice bots included.

The text message warning you is right. It's the call that follows that is lying.

Free SMS · No sign-up · To France

Envoyez votre SMS gratuit en quelques secondes

Pas de compte à créer, pas de publicité, pas de limite : écrivez votre message, indiquez le mobile, et envoyez-le gratuitement depuis votre navigateur.

Envoyer un SMS gratuit