Woman on phone and computer typing password

One-time passcode scam awareness

Most accountholders know not to share their passwords. But many don't realize that sharing a one-time passcode (OTP) can be just as dangerous.

Every day, fraudsters contact consumers pretending to be from a bank, credit union, card processor or fraud department. Their goal is to convince victims to share a security code that was just sent to their phone. Even when the text message sent with the OTP clearly states, “Do not share this code with anyone," scammers use urgency, fear and pressure to persuade people to share it. The FBI reports that criminals commonly impersonate financial institutions and claim there is suspicious activity on an account to obtain one-time passcodes and gain account access.

What these scams look like

Here are a few examples of scams financial institutions frequently hear about:

The fraud alert call

A customer receives a call from someone claiming to be from their institution's fraud department. The caller says a large transaction is pending and must be stopped immediately. A security code arrives by text, and the caller instructs the accountholder to read it aloud "to verify their identity." In reality, the scammer is using the code to access the account.

The locked account scam

A fraudster sends a text claiming the customer's banking account has been frozen. The message directs them to a fake website, where they enter their credentials. Shortly afterward, they receive an OTP and are asked to provide it to "restore access." The code is then used by the criminal to take over the account.

The tech support impersonation

A scammer posing as customer support claims there is a security issue that requires immediate action. They request the OTP sent to the accountholder's phone, saying it is necessary to secure the account. Once shared, the criminal gains access.

Education is one of the best defenses

Financial institutions can make a significant impact by consistently reinforcing one simple message: Never share a one-time passcode.

Remind accountholders to treat any call, text or email asking for an OTP as a red flag, even if it appears to come from their financial institution, SHAZAM® or another trusted organization. Encourage accountholders to end suspicious interactions immediately and contact your institution or the requesting organization directly using a trusted phone number.

Accountholders trust their community financial institutions, and the more often they hear clear reminders, the more likely they are to recognize a scam before becoming victims. To help reinforce this message, you can:

  • Add fraud-awareness signage in branches and ATM areas.
  • Update hold music and call center scripts with short security reminders.
  • Place educational banners on statements, websites and digital banking platforms.

A simple, repeated reminder can help accountholders pause before giving a fraudster the access they need to orchestrate an account takeover.

Resources:
FBI.gov
Internet Crime Complaint Center (IC3)


SHAZAM, Inc., and ITS, Inc., provide this blog for general informational purposes only. The blog may be shared via direct link, provided the content remains unchanged and is presented as originally published. SHAZAM, Inc., and ITS, Inc., assume no responsibility for errors or omissions. By using this blog, readers acknowledge that the information provided does not constitute legal advice and is not a substitute for advice from a qualified, licensed attorney.