Short answer
What to do right now
Contact the affected service or institution through its official route now. Tell them you shared a one-time code with an impersonator and ask what that code approved.
Immediate actions
Find out what the code authorized.
Open the real service through its known app or website.
Tell the service you disclosed a one-time code to an impersonator.
Ask what the code approved, then secure passwords, sessions, recovery details, and recent activity as directed.
Check linked financial accounts and contact them if money or card information may be involved.
Do not
Avoid making the situation harder.
- Do not share a fresh code with anyone who contacts you.
- Do not assume the code only approved the action described by the caller or message.
Records and reporting
Keep the details you already have.
Keep the code alert or message, the time it arrived, the contact that requested it, and any case number from the real service.
Source notes
Official guidance behind these steps
Plainly Living uses the scope and exceptions recorded in its claim-control ledger. These links go to the responsible public agency.
- Federal Trade Commission: How To Avoid a Scam (opens in a new tab)
- Consumer Financial Protection Bureau: What are some classic warning signs of possible fraud and scams? (opens in a new tab)
- Federal Trade Commission: What’s a verification code and why would someone ask me for it? (opens in a new tab)
- Federal Trade Commission: How To Recover Your Hacked Email or Social Media Account (opens in a new tab)
Plainly Living