Skip to content
Likely confidenceCurrent

One-Time Code Sharing Remains a Common Takeover Route

Calls that persuade people to read out a one-time code continue to lead to account takeovers.

Published 10 February 2025

Threat category
Account Takeover
Location
Global
Affected population
Consumers and employees

What we are seeing

Attackers request a password reset, then call the account holder posing as support and ask them to confirm the code that was just sent. The code message itself warns against sharing it.

Why it matters

A one-time code is often the last barrier. If it is shared, the account can be taken over even when the password is strong.

Defensive takeaway

  • Never share a one-time code, even with someone who sounds official.
  • Use an authenticator app where possible.
  • Review active sessions and recovery details regularly.
  • Report unexpected codes to the account provider.
Unverified social-media claims are never presented as fact. Confidence labels reflect how well a claim is corroborated, not how alarming it sounds.

Source

Verified factINSTITUTIONAL

Guidance on phishing and account protection

Microsoft Security · 01 Oct 2024

View source