What Should You Do about an Authentication Code You DIDN’T Request?

We strongly encourage using two-factor authentication (2FA) or two-step verification (2SV) with online accounts whenever possible. The details vary slightly, but with either one, after you enter your password, you must enter an authentication code to complete the login. Although it’s always best to get such codes from an authentication app like 1Password (which enters codes for you), Authy, or Google Authenticator, many websites still send codes by the less secure SMS text message or email. They’re better than nothing.

But what if you receive a 2FA code that you didn’t request?

  1. Don’t panic. Although receiving the code means that someone is trying to log in to your account and has your password, the extra authentication step has done its job and protected your account from being compromised.
  2. Never share an authentication code with anyone! A hacker could attempt to break into your account, be foiled by two-factor authentication, and then email or text you with a trumped-up story about why you should send them the code. Authentication codes are short-lived, so if this is going to happen, it will happen right away.
  3. Independently from the message with the code, go to the account website, log in, and change the password. As always, make sure the password is strong, unique, and stored in your password manager. If the account used an old password that was shared with other accounts, change passwords on those accounts as well.

There are a handful of scenarios that could generate such an authentication code:

  • Stolen credentials: The most likely scenario, which the advice above addresses, is when your email address and password have been stolen, probably in a significant site breach. You can check the Have I Been Pwned site to see if your account is floating around on the “dark Web.” Password managers often perform similar checks. Changing the password on any breached sites is essential.
  • Identity theft: You started receiving authentication codes from TikTok, but you don’t remember creating a TikTok account. Someone might be trying to create an account to impersonate you but cannot complete the account creation without the authentication code. There isn’t much you can do to stop such attempts, although if an account has been created, you should be able to change the password (since it’s using your email address or phone number), log in, and either just let the account sit in your password manager or try to delete it.
  • Accidental or random triggering: If you have a common email address or phone number, someone could have accidentally entered your address or number instead of theirs while trying to create an account. It’s easy to type marsha32@example.com instead of marsha23@example.com or mistake the Boston 617 area code for the upstate New York 607 area code. If you’re sure you don’t have an account at the site in question and you only get one authentication code, you can probably ignore it.

Regardless of the cause, don’t ignore 2FA codes you didn’t request for sites where you have an account. It’s not hard to change a password, particularly if you use a password manager, and the extra piece of mind is worth the few minutes of work.

(Featured image based on an original by iStock.com/Kateryna Onyshchuk)


Social Media: Receiving a two-factor authentication code you didn’t request shows that your security is working, but it’s also an indication that someone may have your password and be trying to break into your account.

Similar Posts

  • Hey Dora…

    So we have Siri and I’ve been playing around with Alexa (don’t tell Grace!) but now I have Dora, too. Dora is the computer from Robert Heinlein’s Time Enough for Love, The Number of the Beast, The Cat Who Walks Through Walls which were some of my favorite Sci-Fi as a kid.

    I was helping a customer that has pretty bad arthritis and struggled to use the keyboard. I was straightening out her email and getting her off of AOL (something we do often!) and noticed how difficult it was to type a simple email. So, I showed her dictation on the Mac and wow, it was like a light just got switched on. Dictation has come a long way and if your are on Mavericks, Yosemite or El Capitan, Apple’s enhanced dictation works wonderfully.

    Dictation will not be a satisfying experience for you if you have a lot of noise in the room, i.e. other people talking, music, etc, but if you are working alone in a relatively quiet environment it can be a great tool not only for dictating that email but you can also use spoken commands to direct your Mac to take action.

    Setting up Enhanced Dictation

    * Open System Preferences, then click on Dictation & Speech. Turn on Dictation and set up your options.

    * Click *Use Enhanced Dictation*. This will download a 1.2GB file so that you can dictate without internet connection.

    * Choose your language and dialect. Some languages, such as English, have multiple dialects.

    * Choose the keyboard shortcut you will use to signal that you’re ready to start dictating. The default is pressing the function Fn key twice, which I find convenient but you can customize it.

    * Choose your preferred microphone from the pop-up menu below the microphone icon. Normally, you use the internal microphone but if you are using a headset or external microphone you can choose that.

    Using Dictation

    * Go to a document or other text field and place the insertion point where you want your dictated text to appear.

    * Press the keyboard shortcut for starting dictation. The default shortcut is Fn Fn (press the Fn key twice). Or choose Edit > Start Dictation. When your Mac is listening, it displays a microphone with an input meter that rises and falls as you speak.

    * Speak the words that you want your Mac to type. Use dictation commands to add punctuation, formatting, and more.

    * To stop dictating, click Done below the microphone icon, or press Fn, or switch to another window.

    The more you use Dictation, the better it understands you. Dictation learns the characteristics of your voice and adapts to your accent.

    I will go into some of the more enhanced features like Dictation Commands in next week’s Kibbles & Bytes but I can tell Dora to Open an App, select text, move up or down and much more. I think you will like dictation on the Mac, give it a try!