A text arrives: a six-digit code, sent because someone is trying to log into one of your accounts. Then a call or a message follows, asking you to read that code back or forward it. This single move is behind a large share of account takeovers reported to authorities: the FTC received over 2.6 million fraud reports from consumers in 2023, and consumers reported losing $10 billion to fraud that same year. The code itself does the damage — not malware, not a hacked password.
How a Six-Digit Code Becomes a Stolen Account
The attack starts with something you already gave away without realizing it: your phone number, tied to an email or username found in a leaked database. The scammer enters your phone number and your email into a login page for a bank, a messaging app, or a marketplace account. The platform, following its normal security process, sends a one-time verification code to your phone to confirm it’s really you. Seconds later, the scammer contacts you directly — by text, by call, sometimes posing as a delivery driver, a bank employee, or a support agent — and asks you to read out or forward the code you ‘accidentally received.’ The moment you comply, they finish the login on their end. From that point, the account belongs to them: your number, your password reset options, your two-factor setup — all can be quietly changed before you notice anything is wrong. This pattern explains why the numbers cited above are so large: fraud reported to the FTC spans many categories, but account takeover through a hijacked verification code remains one of the fastest and cheapest methods available to a scammer, since it requires no technical break-in at all, only a convincing phone call or text at the right moment. The scammer doesn’t need to guess your password or bypass any encryption; they need only borrow your voice or your thumb for the few seconds it takes to relay six digits. What makes this method so durable is that it exploits trust in a system designed to protect you. The verification code exists precisely because platforms assume a stranger shouldn’t be able to log in without proving they hold your phone. The scam doesn’t defeat that system technically — it defeats it socially, by convincing the rightful owner of the phone to become the weak link in a chain that was otherwise sound. That’s also why these attacks scale so easily: a single script, reused across thousands of targets pulled from a leaked contact list, can generate a steady trickle of successful takeovers simply by playing the odds that a fraction of recipients will comply without thinking twice.
A Familiar Message
The following is an illustrative scenario, not a real case, meant to show how this scam typically unfolds.
Imagine receiving a text from a delivery company saying a package couldn’t be delivered and a code is needed to reschedule. Minutes earlier, an unrelated verification code arrived from a shopping app. The two messages look unconnected, but they aren’t: the shopping account is being logged into elsewhere, and the ‘delivery’ text is the same person asking for that code under a different name. Someone who forwards it, thinking it settles a shipping problem, later finds the shopping account’s saved payment method used for a purchase they never made, and the password already changed. By the time the victim realizes what happened, the scammer has often also changed the recovery email and phone number on file, locking the original owner out of their own account and turning what looked like a minor shipping inconvenience into a drawn-out dispute with customer support, a bank, or both. The disorientation that follows is part of what makes this scenario so effective: the victim isn’t reacting to an obvious threat, they’re reacting to something mundane — a missed delivery — which is exactly why the guard usually reserved for suspicious-looking requests never gets raised in time.
How to Stop This Before the Code Ever Leaves Your Phone
The fix is less about technology and more about a fixed rule: a verification code is not meant to be shared with anyone, under any framing, ever. Legitimate companies never ask you to read or forward a one-time code — they only ask you to enter it yourself, on the site or app you’re actively using. Building a few habits around your phone number closes most of the door.
Treat every code request as suspicious by default
If a code shows up on your phone without you actively trying to log into something, that’s the signal something is wrong — someone else is attempting access using your number or email. Do not read it aloud, do not forward it, do not type it into any chat, even one that claims to be customer support. Delete the message once you’re sure you didn’t request it, or take a screenshot before deleting in case you need to report it later.
Verify the request through a separate channel
If a call or text claims to be from your bank, a delivery service, or a platform you use, hang up or ignore the message and contact that organization directly through the number or app you already know, not one provided in the suspicious message. Genuine support staff can look up your account without needing a code you were just sent.
Separate your phone number from your most sensitive accounts
Where possible, use an authenticator app instead of SMS for two-factor authentication, since app-based codes aren’t tied to a number that can be socially engineered over a text exchange. For accounts or signups that don’t need your real number at all, a secondary or virtual number keeps your main line out of databases that eventually leak or get sold.
Slow the exchange down on purpose
Scammers rely on urgency to keep you from thinking clearly — a package about to be returned, an account about to be locked, a payment about to fail. Whenever a message pushes you to act within minutes, treat that pressure itself as a warning sign. Taking even thirty seconds to pause, put the phone down, and reconsider the request is often enough to break the script the caller or texter is relying on. It also helps to tell a trusted friend or family member out loud what the message is asking you to do; saying the request aloud to someone else frequently exposes how strange it sounds the moment it leaves the pressured context of the phone screen.
Why a Second Number Reduces This Exposure
Verification-code scams work because your phone number sits at the center of your identity online: it’s tied to your bank, your email recovery, your shopping accounts, and often ends up in data broker lists after a single leaked signup form. A phone privacy app that provides a secondary, disposable number lets you keep your primary number reserved for the handful of accounts that truly need it — banking, close contacts, official services — while everything else, from retail signups to one-off verifications, goes through a number that can be swapped or dropped if it starts attracting unwanted messages. This doesn’t make you invisible or exempt from any verification process; it simply narrows the number of places your real number appears, which narrows the number of ways a scammer can target you with a fake code request in the first place. Fewer entry points means fewer opportunities for the kind of social engineering described above to even reach your main line. Over time, this also reduces the volume of unsolicited texts and calls reaching your phone altogether, since a number that never appears in marketing databases or resold contact lists has far fewer chances of being scraped into the lists scammers buy and dial through in bulk.
Numero eSIMaffiliate link
A second number without a SIM card, in 80+ countries
