Most of us have been told that two-factor authentication (2FA) is the single best thing we can do to protect our accounts. That advice is still correct. But scammers have adapted, and their new goal is simple: get you to hand over the six digits yourself, or wear you down until you tap "Approve".
A one-time password is the last lock on the door. If a criminal already has your username and password from a data breach, that code is the only thing standing between them and your bank account, email, or cryptocurrency exchange.
Method 1: The Real-Time Relay
You click a link in a text message about a delivery, a bank alert, or a marketplace sale. The login page looks perfect, because it is a live mirror of the real site. As you type your username and password, the scammer's server passes them straight to the genuine bank in real time.
The bank then sends you a legitimate OTP. It arrives from the real short code, with the real wording, at exactly the moment you expected it. You type it into the fake page, the scammer relays it, and they are inside your account within seconds. Nothing about the code itself was fake. Only the page you typed it into.
Method 2: The Voice Assist
Here the scammer calls you first, posing as your bank's fraud team, a courier, or a buyer on a marketplace app. They tell you a verification code is on its way and ask you to read it back to confirm your identity. In reality, they have just triggered a password reset on your account, and the code you are about to read out is the reset code.
The rule is absolute: no bank, platform, or delivery company will ever phone you and ask you to read out a code. The messages themselves usually say so in the text you are skipping past.
Method 3: Push Fatigue
If your 2FA uses an app that asks you to tap "Approve", the attack is even cruder. Having stolen your password, the scammer triggers login attempt after login attempt. Your phone buzzes at 2am, again and again, until you tap Approve just to make it stop, or tap it by accident while half asleep.
Method 4: The SIM Swap
Occasionally the scammer skips you entirely. Using personal details gathered from social media or a breach, they persuade your mobile provider to port your number to a SIM card they control. Your phone loses signal, and every SMS code now goes to them. A sudden and unexplained loss of mobile service is an emergency, not an inconvenience.
How to Protect Yourself
- Never enter a code on a page you reached from a link: Close the message, open the app or type the address yourself, then log in. If the alert was genuine, it will be waiting for you there.
- Never read a code out loud: Not to a caller, not to a "buyer", not to anyone. Hang up and call the organisation back on the number printed on your card or on their official site.
- Read the whole SMS, not just the digits: The message states what the code authorises. If it says "password reset" and you were not resetting a password, someone else is.
- Treat an unexpected push notification as a break-in: Deny it, then change that account's password immediately. An unrequested prompt means your password is already compromised.
- Move off SMS where you can: An authenticator app is harder to intercept than a text message, and a hardware security key or passkey is better still, because it will not authenticate to a lookalike domain at all.
- Lock down your mobile account: Ask your provider to add a port-out PIN or transfer lock so your number cannot be moved without it.
Two-factor authentication has not failed. What fails is the assumption that a code arriving from a genuine sender means the page or the person asking for it is genuine too. The code proves who you are to the service. It proves nothing about who is standing on the other side.