US blog
Recovery

What to do if you gave a scammer a one time code

If you gave a scammer a one time code, act fast. Learn what the code may have allowed, which accounts to secure first, and when to call your bank.

One time code message with a warning not to share it

If you gave a scammer a one time code, treat the account as exposed.

The code may have helped them log in, add a device, reset a password, approve a transfer, or change security settings. Do not keep texting them. Do not argue. Do not send another code.

Go to the real app or website yourself, or call the bank from the number on your card.

What the code may have done

Code was forWhat may have happenedFirst move
Bank loginThey may have logged inCall the bank now
Card or transfer approvalThey may have approved a paymentAsk the bank to review transactions
Email loginThey may control your reset keyChange email password and revoke sessions
Phone carrierThey may try SIM swap or account changesCall your carrier
Social accountThey may take over the accountChange password and remove unknown devices

Do this now

  1. Stop talking to the scammer.
  2. Open the real app yourself.
  3. Change the password for the affected account.
  4. Sign out of unknown devices.
  5. Remove unknown recovery emails or phone numbers.
  6. Call the bank, carrier, or platform if money or identity is involved.
  7. Save screenshots of the message and number.
  8. Report the scam.

If this was a bank code, call the bank first. Password cleanup can wait ten minutes. Unauthorized transfers cannot always wait.

Change these passwords next

Start with:

Use unique passwords. If you reused the same password anywhere, change it there too.

How to avoid the next code trap

The rule is simple:

No one gets a code you did not ask for.

Not your bank. Not "fraud support." Not a delivery company. Not someone claiming to be your child. Not a buyer on Marketplace. Not a caller who says they need to "verify" you.

If someone needs a code from you, the safest answer is no.

Sources