What Should You Do about an Authentication Code You DIDN’T Request?

We strongly encourage using two-factor authentication (2FA) or two-step verification (2SV) with online accounts whenever possible. The details vary slightly, but with either one, after you enter your password, you must enter an authentication code to complete the login. Although it’s always best to get such codes from an authentication app like 1Password (which enters codes for you), Authy, or Google Authenticator, many websites still send codes by the less secure SMS text message or email. They’re better than nothing.

But what if you receive a 2FA code that you didn’t request?

  1. Don’t panic. Although receiving the code means that someone is trying to log in to your account and has your password, the extra authentication step has done its job and protected your account from being compromised.
  2. Never share an authentication code with anyone! A hacker could attempt to break into your account, be foiled by two-factor authentication, and then email or text you with a trumped-up story about why you should send them the code. Authentication codes are short-lived, so if this is going to happen, it will happen right away.
  3. Independently from the message with the code, go to the account website, log in, and change the password. As always, make sure the password is strong, unique, and stored in your password manager. If the account used an old password that was shared with other accounts, change passwords on those accounts as well.

There are a handful of scenarios that could generate such an authentication code:

  • Stolen credentials: The most likely scenario, which the advice above addresses, is when your email address and password have been stolen, probably in a significant site breach. You can check the Have I Been Pwned site to see if your account is floating around on the “dark Web.” Password managers often perform similar checks. Changing the password on any breached sites is essential.
  • Identity theft: You started receiving authentication codes from TikTok, but you don’t remember creating a TikTok account. Someone might be trying to create an account to impersonate you but cannot complete the account creation without the authentication code. There isn’t much you can do to stop such attempts, although if an account has been created, you should be able to change the password (since it’s using your email address or phone number), log in, and either just let the account sit in your password manager or try to delete it.
  • Accidental or random triggering: If you have a common email address or phone number, someone could have accidentally entered your address or number instead of theirs while trying to create an account. It’s easy to type marsha32@example.com instead of marsha23@example.com or mistake the Boston 617 area code for the upstate New York 607 area code. If you’re sure you don’t have an account at the site in question and you only get one authentication code, you can probably ignore it.

Regardless of the cause, don’t ignore 2FA codes you didn’t request for sites where you have an account. It’s not hard to change a password, particularly if you use a password manager, and the extra piece of mind is worth the few minutes of work.

(Featured image based on an original by iStock.com/Kateryna Onyshchuk)


Social Media: Receiving a two-factor authentication code you didn’t request shows that your security is working, but it’s also an indication that someone may have your password and be trying to break into your account.

Similar Posts

  • _Dear Friends_,

    Well I didn’t win the Powerball so I guess I have to stick with my day job a bit longer. Vermont finally got some winter weather and more snow is in the forecast. It has even gotten a bit cooler down here in the Keys where when it dips below 70° F the down coats and shoes come out.

    I am still struggling a bit with tropical gardening. A large caterpillar ate the leaves off one of my tomato plants overnight and for some reason I cannot get my citrus trees to blossom. I keep feeding and watering them in the hopes that my Key Limes, Myers lemon and Naval oranges will blossom but they seem to just make greenery. We did discover that bananas love coffee grounds and since Grace and I produce a lot of coffee grounds those plants are doing well.

    I upgraded myself from the original iPad mini to the iPad mini 4 before I went to Las Vegas and the differences are remarkable. Not only is it thinner and lighter but the screen is much better, the speed is a lot faster and I simply love the Touch ID. I had been trying to activate my old iPad mini with my finger after being used to that with my iPhone so it is a welcome addition for my primary reading device. I prefer the iPad mini to the full-size iPad or the iPad Pro because of the size. It feels like a paperback book in my hand and even on a crowded airplane it is comfortable to use.

    Do you know about tethering? I don’t know how many people I have talked out of buying a cellular iPad by explaining tethering. I guess that is a bit against my interests as you pay an extra $130 for cellular versions of the iPad. If you buy that cellular version you also need a cell contract which might be another $30 a month. Tethering is a much better idea. Tethering is where you share the cellular connection from your iPhone with your iPad. You activate Personal Hot Spot and boom you have your own private wireless network over cellular. The other day Comcast had an outage here in the Keys and I used tethering with my Mac to work all day. Most carriers will charge you a little more for tethering but it is less than the $30. With my iPad, I simply choose “donphone” from the wireless setup and I am connected with the same speed as if I had the cellular version of the iPad.

    This week’s Kibbles & Bytes exclusive is a “**fully configured 13-inch MacBook Air.**”:http://www.smalldog.com/wag900002125/special-save-50-on-apple-refurbished-macbook-air-and-free-hammerhead-case This Apple factory reconditioned MacBook Air carries the same 1-year Apple warranty as new Macs and we are bundling it with AppleCare so you actually get 3-years of warranty protection and 3-years of free Apple technical support instead of the normal 90-days. This MacBook Air is the same as the one I use and love. It features a 1.7GHz i7 processor, 8GB of ram and a big 512GB SSD drive. I am going to take $50 off and include a free Hammerhead neoprene case for this MacBook Air. Regular price is $1639.97 but for Kibbles & Bytes readers this week only (while supplies last) the price for this bundle is “**$1559.98.**”:http://www.smalldog.com/wag900002125/special-save-50-on-apple-refurbished-macbook-air-and-free-hammerhead-case

  • Get Organized!

    I have tried a lot of apps over the years for keeping ideas organized, assigning tasks or just keeping track of my goals. The problem I’ve found with many of the organizational applications is that I don’t find them easy to access. If you’re not on your phone or at your computer, often these applications can’t be utilized easily or have widely varied interfaces depending on which device your using.

    “**Trello**”:https://trello.com/ has become my new favorite go-to app for keeping ideas and tasks organized. Trello is a free app with the ability to also pay for upgraded features for minimal fees. Why do I love Trello so much? It’s simple, I can easily use it on my computer, my iPhone or my iPad. There is an app for all three of my devices, and each version works seamlessly with the others. Working with several staff members in different departments here at Small Dog can make keeping track of tasks and to-do lists a bit of a challenge, but this simple application has really helped to streamline things.

    I easily and quickly create what they call “boards”, each board then allows you to create individual categories to which you can then add individual tasks. Within my lists I can upload photos, files, web links, assign due dates and add notes. Once I have created a board, I can also easily share that board with co-workers or whomever I choose to share them with. Anyone I have shared a board with can also be granted access to update and add to the boards, add notes or more files.

    A feature many of us have come to really rely on are the updates that you get from Trello notifying you that someone has made a change. I have found just one complaint thus far about the application. There appears to be no feature to mark a task as completed while still leaving it on your board. You can easily archive tasks and even entire boards, but I prefer to still be able to see those tasks while clearly seeming them marked as completed. However, all in all, I find this to be an invaluable app and one that I utilize all of the time. I have tried and do use google docs and google drive, and I’ve installed those on my devices as well, but for me nothing beats the ease and convenience of Trello.