SMS Security
Why Am I Getting One-Time Codes I Did Not Request by Text?
Unexpected one-time codes can come from login attempts, password resets, typos, app glitches, or phishing. This guide explains what they do and do not prove and how to secure accounts safely.
Do not share the code
If you are getting one-time codes by text that you did not request, do not share the code with anyone. The message may come from a real login attempt, password reset, typo, app error, or scam. Open the account's official app or website and review security activity.
A code does not always mean someone got into your account. Often it means someone started a sign-in or reset flow and still needs the code to continue.
Your main job is to deny access by not sharing the code, then secure any account connected to the message.
Why unexpected codes happen
Someone may have typed your phone number by mistake, tried to log into an account, attempted password recovery, or used your number during fraud. Scammers may also call or text pretending they need the code to fix an error.
The FTC warns that scammers ask for verification codes to take over accounts. A real company should not ask you to read a one-time code to an unexpected caller or texter.
If the messages name a service you use, treat them more seriously and review that account.
- Login attempt.
- Password reset request.
- Phone number typo.
- Account creation attempt.
- Scammer trying to obtain the code.
- Carrier or app security process.
Check exposure and connected accounts
If your phone number or email appears in known exposure data, you may receive more targeted code requests and phishing texts. A match does not prove account access.
Only check identifiers you own or are authorized to manage. Never enter a code, current password, SSN, card number, passport number, or bank details into an exposure checker.
Secure the named account
If the text names a service you use, open that service directly. Change a reused password, enable MFA, review recent activity, and sign out unknown sessions.
If the account supports authenticator apps, passkeys, or security keys, consider using those instead of SMS.
Protect your phone number
Set or reset your carrier PIN and ask about SIM swap or port-out protection. The FCC warns that phone-number takeover can affect verification codes.
Review carrier account activity if codes appear alongside sudden service changes.
Handle repeated code messages
Do not reply with codes. Block obvious scam senders, report spam through your phone or carrier, and keep evidence if the messages relate to financial or identity harm.
If the same account keeps sending codes, contact the provider through official support.
- Do not share codes.
- Do not approve prompts.
- Review the account directly.
- Secure the carrier account.
- Report repeated scam texts.
Change reused passwords
A code request may mean someone knows or is guessing your password. If the account password is reused, change it everywhere it appears.
NIST recommends password managers to create and store unique passwords.
Know when to escalate
Escalate if codes are followed by successful login alerts, bank activity, phone service loss, changed recovery settings, or accounts you did not create.
Use official provider, carrier, FTC, or FBI IC3 reporting resources depending on what happened.
Frequently asked questions
Does receiving a code mean someone has my password?
Not always. It may be a reset attempt, typo, or login attempt. Review the account if it is yours.
Should I reply STOP?
For legitimate short-code messages it may work, but for suspicious texts avoid engaging and report or block instead.
Can someone use the code without me?
If the code is required and you do not share it, the attacker usually cannot complete that step.
Sources
This guide is reviewed against official guidance. External pages may be updated by their respective owners.
