Likely confidenceCurrent
One-Time Code Sharing Remains a Common Takeover Route
Calls that persuade people to read out a one-time code continue to lead to account takeovers.
Published 10 February 2025
- Threat category
- Account Takeover
- Location
- Global
- Affected population
- Consumers and employees
What we are seeing
Attackers request a password reset, then call the account holder posing as support and ask them to confirm the code that was just sent. The code message itself warns against sharing it.
Why it matters
A one-time code is often the last barrier. If it is shared, the account can be taken over even when the password is strong.
Defensive takeaway
- Never share a one-time code, even with someone who sounds official.
- Use an authenticator app where possible.
- Review active sessions and recovery details regularly.
- Report unexpected codes to the account provider.
Unverified social-media claims are never presented as fact. Confidence labels reflect how well a claim is corroborated, not how alarming it sounds.
Source
Verified factINSTITUTIONAL
Guidance on phishing and account protection
Microsoft Security · 01 Oct 2024
View source