I gave a scammer my 2FA verification code, what now?
Last reviewed: 2026-08-01 · Checked with Hunch’s on-device engine, the same one inside the extension. How Hunch checks →
Part of our guide: What to do if you got scammed →
A verification code is a one-time key, and the fix is simple even if it feels alarming: get back into the account and change what the code unlocked before the scammer settles in. Act quickly and you can usually shut them out entirely.
Got a message like this? Paste it here →
Code-theft scams target people who use two-factor authentication and have been taught it keeps them safe, so a request to 'confirm' a code feels like security, not danger. The scammer already holds your password or number and only needs that final digit string. It works best under time pressure, when reading back six numbers seems quicker than stopping to think.
Illustrative example of the pattern, not a real message someone received.
How to verify it yourself
- Identify which account the code was for, the text or email that delivered it says which service requested it.
- Go straight to that service and change the password, which forces the scammer's session to log out.
- Reset two-factor authentication so a brand-new code is required, invalidating anything they captured.
- Remember the rule: no real company or support agent ever asks you to read back a code, the code is meant for you alone.
Common questions
I gave someone my verification code what can they do
A code lets them complete a login or a password reset on that account at that moment. Change the account's password immediately to cut off the session they may have opened.
how do I lock a scammer out after sharing my 2FA code
Change the password and reset two-factor authentication on the affected account right away. That logs out existing sessions and makes the captured code useless.
can a scammer get into my account with just the code
Often the code is the final piece they need after already having your password or phone number, so treat the account as reachable. Changing the password now closes that door.
does changing my password stop them if they have the code
Yes, a verification code is single-use and expires quickly, so once you change the password and reset 2FA, the old code can't be reused. Sign out all other sessions to be sure.
If you already responded
- Go to the account the code belonged to and change its password immediately, which ends any session the scammer just opened.
- Reset two-factor authentication on that account so a fresh code is required and any code you shared becomes worthless.
- Open the account's device and session list and sign out every login you don't recognize.
- If the code was for a phone or messaging account, check that no forwarding, recovery email, or linked device was quietly added, and remove anything you didn't set up.
- Report it at reportfraud.ftc.gov, and if the account holds personal data, at IdentityTheft.gov. Then ignore any 'account support' follow-up asking for another code, that request alone marks it as a scam.
If you were already hit, expect a follow-up
One more thing to expect: after a scam, your details often land on lists that get reused, so you may be contacted again, sometimes by people posing as investigators, your bank's "fraud team," or "recovery agents" who promise to get your money back for an upfront fee. That follow-up is a second scam. No legitimate service charges a fee to recover funds.