One-Time Passwords: Why You Must Never Share Them
An OTP is a signature for a specific action: a payment, a login, a new device. Why no genuine person ever needs yours, who might ask, and how to read the message before acting.

A one-time password (OTP) is a short code sent by text, email or app. It works like a signature: it says "yes, I approve this specific action". Whoever enters it gets that approval. That is why every scammer wants yours.
What a code can authorise
- A payment or transfer.
- Logging in to online banking.
- Adding a new device or phone to your account.
- Changing your PIN, password or phone number.
- Registering WhatsApp. See the WhatsApp code scam.
Read the message
Who asks, and what they say
- "Bank staff": "Read me the code to cancel the fraudulent payment." See bank impersonation.
- Buyers: "Send the code so I can pay you."
- Friends' hacked accounts: "I sent a code to you by mistake."
No genuine person ever needs your code. Not your bank, not a buyer, not a friend.
Stronger alternatives exist for many accounts. See why text codes are weaker. For more, see the complete guide to financial scams.
Frequently asked questions
Why do banks send OTPs?
To confirm it is really you approving a specific action, such as a payment, login or adding a new device.
Who might ask for my OTP?
Scammers posing as bank staff, delivery companies, buyers, employers or friends. No genuine person needs it.
I shared an OTP. What now?
Call your bank on the number on your card immediately, and check what the code was for.
Sources
- Take Five to Stop Fraud, Take Five (UK Finance)
- Mobile Payment Apps: How To Avoid a Scam When You Use One, US Federal Trade Commission
- More than a Password, US Cybersecurity and Infrastructure Security Agency


