Verification codes by SMS you never asked for: what they mean

You are having dinner and a text arrives with a six-digit code to sign in to your account. You are not signing in anywhere. Most people delete it, assuming the app misfired. It did not: it is the clearest signal you will ever get that somebody has your password.
The message always reads about the same: “Your verification code is 481902. Do not share it with anyone.” It comes from your bank, from Instagram, from your email or from a shop. And you are not signing in anywhere.
The common reaction is a shrug and a delete. That is the wrong reaction, because the message carries valuable information.
What has actually happened
For a service to send you a code, somebody had to reach the screen that asks for it. And you only reach that screen after typing a correct username and password.
Put plainly: whoever tried already had your password. The only thing they lacked was the second factor.
That is bad news and good news at once. The bad: your password is compromised, most likely from an old breach of the kind that feeds credential stuffing. The good: two-step verification just did its job in front of you.
The three possible situations
1. A genuine login attempt. The leading explanation, especially if the code is for an important account or the message repeats.
2. Somebody else’s mistake. A stranger fat-fingers a digit when typing their own number at sign-up and the code lands on your phone. It happens. The tell: it is a service you do not use, it does not repeat, and the message talks about a new registration rather than a sign-in.
3. A scam already in progress. The dangerous one. The code is real, but seconds later you get a message or a call from someone claiming to be from the service, asking you to read that number out.
The code scam: how it works
It is so simple it is disarming.
The scammer has your password and triggers the code. Immediately they message you: “This is the security team at [service]. We have detected a suspicious login. To block it, please confirm the code you have just received.”
And the code did arrive genuinely, from the official number, with the official wording. That coincidence is what convinces people.
There is a variant used heavily on second-hand marketplaces: a supposed buyer says they want to “check you are a real person” and sends you a code, asking you to read it back. That code is either the sign-in code for one of your accounts, or the registration code for a messaging service using your number.
No service anywhere asks for a verification code by phone, by message or by email. None. If somebody asks you for one, it is a scam. There are no exceptions to memorise.
The same idea with more context is in how to spot a phishing email.
Authentication fatigue
The variant aimed at accounts that use approval prompts instead of codes. The attacker fires login attempts over and over, sometimes in the small hours, until the victim approves one to make it stop, or taps it half asleep.
If it happens to you: approve none of them, silence notifications for a while, and change the password. An approval given out of exhaustion counts exactly as much as one given on purpose.
What to do, in order
- Do not enter the code anywhere and do not pass it to anyone.
- Change that account’s password, going in through the app or typing the address by hand. Never through a link in the message.
- If that password was reused elsewhere, change it there too. Full procedure: what to do if your password is leaked.
- Review the account’s active sessions and end any you do not recognise.
- Move from SMS to an authenticator app if the service allows it.
Why it is worth leaving SMS behind
An SMS code beats having nothing, but it is the weakest method available:
- It can be read on the lock screen without unlocking the phone.
- It is vulnerable to SIM swapping, where somebody persuades the network to move your number to another SIM.
- It depends on having signal.
An authenticator app generates the numbers on the phone itself, with no network and no mobile operator in the middle. A physical key goes further still, and cannot be given away over the phone because it has to be physically present. The full comparison is in two-factor authentication explained.
Before switching, store your recovery codes somewhere other than the phone: you lost the phone with your two-factor codes.
The short version
- A code arriving unrequested means somebody already has your password.
- Do not delete it: change that password the same day.
- Nobody legitimate will ever ask you for that code, through any channel.
- Many prompts in a row is authentication fatigue: approve none.
- SMS is the weak link; an authenticator app is free and better.
Frequently asked
The questions that keep coming up
Why am I getting verification codes I did not request?
Because somebody is trying to get into your account and has already cleared the password step. The system asks them for the second factor, and the message lands on your phone. It can also be a stranger mistyping their own number, but if it repeats, the first explanation is the right one.
Does it mean I have been hacked?
It means somebody has your password, not that they got in. As long as you never hand over the code, two-step verification is doing exactly its job.
What should I do when one arrives?
Do not enter it anywhere, do not forward it to anyone, and change that account's password immediately from the official app — never from a link in the message.
What if I get lots in a row?
That is authentication fatigue: they bombard you hoping you approve one out of exhaustion or by mistake. Approve none of them and change the password straight away.


