Many users of social media platforms and digital applications face the suspicious situation of receiving a text message containing a “verification code” (OTP) without having applied for it, which is considered a security indicator that calls for caution.

The arrival of this code often means that another person is trying to access the account and already has the username or password, but the last line of defense represented by “two-factor authentication” prevents him from completing the login process, while the reason may sometimes be due to an error in writing the phone number by another user or an attempt by the hacker to confuse the target.


To protect the account from hacking attempts, cybersecurity experts stress the necessity of ignoring the message and not sharing the code at all, taking the initiative immediately to change the password to a strong one, reviewing the list of connected devices to log out of any strange device, in addition to preferring to rely on authentication applications instead of SMS.