Received a Verification Code You Did Not Request? What to Check

Received a Verification Code You Did Not Request? What to Check

A code arrives for something you did not do. The message itself does not tell you why it was sent, and that is the difficulty: the same SMS is consistent with several very different situations.

TL;DR: Do not relay the code to anyone who contacts you about it, and do not act on links or numbers inside the message. Google’s guidance for an unrequested code is to disregard and delete it, and not to share it. Beyond that, what is worth doing depends on what else you can observe — whether the code names an account you actually use, whether more codes follow, whether anything looks different on that account, and whether your phone service is behaving normally.

The three things to do first

  1. Do not relay the code. If anyone contacts you asking for a sign-in, registration or recovery code — by call, chat or message — do not give it to them. Use only a flow that you started, inside the service’s own app or site.
  2. Do not act on the message’s own links or phone numbers. A code arriving does not make the surrounding text genuine.
  3. If the code names a service you use, open that service yourself — its official app, or its address typed by you — and look at the account from there.

Google’s help on unrequested verification codes states that you can disregard and delete the message and should not share the code, and points to its Security Checkup for a broader review.

What it could mean

The message alone does not distinguish these. Microsoft’s troubleshooting page for unrequested codes names three possibilities directly:

  • Someone is trying to access an account.
  • Someone entered the wrong phone number or email when signing in.
  • A code you requested earlier was delayed and has only now arrived. If you are unsure which channel an earlier request used, where verification codes actually go covers reading the destination.

Two more are worth holding in mind:

  • The message may be bait. A code-shaped message can accompany an attempt to get you to call a number, follow a link, or read the code to someone.
  • The number may carry a previous holder’s history. Numbers are reassigned, which is the same mechanism behind a number that arrives already registered on WhatsApp.

These are possibilities, not a diagnosis. Deciding between them takes something beyond the SMS, such as the account itself.

What to look at, by what you can observe

What you can observe What it is consistent with Proportionate response
One code, for a service you do not use Wrong number entered, a delayed message, or an attempt against an account that is not yours Disregard and delete it; do not enter it anywhere
One code, for a service you do use Any of the possibilities above, including an attempt Open that service yourself and review its security page
More codes arriving Repeated attempts, or a service retrying Review the named account’s security settings and strengthen its sign-in
Someone contacts you asking for the code An attempt to obtain it from you Do not relay it; end the contact; report through the service’s official channel
Something unfamiliar on the account — a session, device or changed recovery method Possible access Use the service’s own controls, starting with the recovery methods
Phone service stops working unexpectedly An outage, a device or SIM fault, or a change to the line Contact your carrier — see below

Recovery methods deserve the closest look

If you inspect one part of an account after an unexpected code, make it this one.

Access to an account can be made durable by changing its recovery methods — the backup email, the recovery phone, trusted devices, linked sessions. Restoring a password does not necessarily undo that, because the route back in has been repointed.

So on the account’s security page, look specifically for:

  • a recovery email you no longer recognise or cannot open;
  • a recovery phone number that is not yours;
  • linked devices or active sessions you do not recognise;
  • connected apps or app passwords, whose behaviour after a password change varies by service — check the service’s own documentation rather than assuming they are revoked.

Google documents reviewing account activity and devices for its own accounts.

If your phone loses service

Losing mobile service has ordinary causes: a network outage, a damaged or dislodged SIM, a device fault, a billing issue.

It can also accompany a change to the line itself. What makes that worth a prompt call to your carrier is the combination — service stopping with no ordinary explanation, particularly alongside messages about account changes, number transfers or port requests you did not initiate.

Contact your carrier through a number you look up yourself, not one from a message. As one carrier example, AT&T’s guidance in the United States asks customers who suspect an illegal number transfer to contact it promptly; other carriers have their own procedures and contact routes, so use your own provider’s. Loss of service alone does not establish that a number has moved; it is a reason to check quickly, because control of a line governs SMS-based sign-in and recovery.

Two situations worth walking through

Illustrative scenarios, not reports of real accounts.

A code from a service you have never used. It names a marketplace you have no account with. There is nothing of yours to secure. Disregard and delete it, and do not create an account there to investigate — that turns a stray message into a real footprint. If more arrive from the same service, its own security or help channel is the place to report them; marketplaces publish guidance, for example Shopee’s account-security help. WhatsApp similarly publishes guidance for a code you did not request.

A code from a service you do use, twice in ten minutes. Here you have something to inspect. Open the service’s own app, go to its security page, and read the sign-in activity, the devices, and the recovery methods in that order. If everything matches what you expect, strengthening sign-in is a reasonable response. If instead the account is refusing a number you are trying to add, that is a different problem — see what Google’s phone-number rejection means. If a recovery method is one you do not recognise, that is the finding, and the service’s own recovery and security controls are where it gets handled.

If you already gave the code to someone

This happens, and the pressure applied is designed to work. What to do depends on whether you can still get into the account.

If you still have access:

  1. Open the service directly — its app, or its address typed by you.
  2. Review the recovery methods first and restore any that were changed.
  3. Review linked devices and active sessions. Sign out ones you do not recognise; be careful about signing out everything at once if a session you still hold is your only way in.
  4. Change the credential the service actually uses. Not every service uses a conventional password — WhatsApp, for instance, is organised around the registration number and the two-step PIN or password offered by the app — so use whatever that service’s security page offers.
  5. Turn on the strongest second factor available, noting that a sign-in factor is not automatically a recovery method.

If you are already locked out: go straight to the service’s official account-recovery process. Do not keep trying alternative sign-ins, and do not engage with whoever contacted you.

If money moved or actions were taken, report to that service’s official response channel directly — a payment provider, bank or marketplace has its own process for that.

No sequence guarantees that every consequence is undone. The aim is to close the routes back in.

If you want to report it

Report through the official channel of the service the message claims to come from. Useful to include:

  • that you received a verification code you did not request;
  • the approximate date and time;
  • the service or sender name shown;
  • your number masked to its last digits.

Keep out of any report: the code itself, passwords, and recovery codes. Redacted evidence — a screenshot with the code blacked out, for instance — is a different thing from the code itself. Follow the evidence requirements of the form you are using, while keeping codes, passwords and recovery codes out of it.

If you rent an inbox from us, remember that a rented number may carry prior associations and may be reassigned afterwards, so a message that has nothing to do with you is an unremarkable outcome rather than a signal about your account. An unexpected message on its own does not establish that anything of yours is affected. But if the code names a service you actually use, treat it like any other account of yours and inspect it normally. If you believe an order is wrong, a support ticket with the order ID is the route, and the FAQ sets out what an order does and does not establish.

Limitations of this guide

  • A single message does not establish who requested a code or why. We cannot identify the initiating person from a received SMS; the destination service may hold activity records, and even those do not establish a person’s identity.
  • The possibilities listed are possibilities. Distinguishing them requires the account, not the message.
  • Security controls and their names differ by service and change over time. The service’s own security page is authoritative.
  • No sequence of steps guarantees a compromise is fully reversed.

FAQ

Does one unexpected code mean my account was accessed?

No — it is consistent with several situations, including a wrong number entered, a delayed earlier request, and an attempt that did not succeed. For a lone code, Google’s guidance is to disregard and delete it without sharing it.

Someone says they sent it by accident and asks me to forward it. Should I?

No. Do not relay a sign-in, registration or recovery code to anyone who contacts you. If their request is genuine, they can start the flow again themselves.

Can you find out who requested the code?

We cannot. A received SMS does not carry that, and we have no visibility into the requesting service. The service itself may hold activity records, but those show requests and devices rather than establishing a person’s identity.

I keep getting codes from the same service. What now?

If it is an account you use, open it directly and review sign-in activity, devices and recovery methods, then strengthen sign-in. If it is not your account, there is nothing of yours to secure; report through that service’s official channel rather than signing up to investigate.

My phone lost service around the same time. Is that connected?

It may be, and it may be an outage, SIM or device fault. The combination worth acting on quickly is unexplained loss of service together with notifications about account changes or number transfers you did not start. Call your carrier on a number you look up yourself.

Would a different phone number stop this?

Not as a general answer — any number can receive a stray code, and the protection for an account lies in its own controls. A number change is a decision for specific circumstances, such as sustained unwanted contact, rather than a routine response to one message.

I got a code on a rented number. Does that mean something is wrong?

Not by itself. A rented number may carry prior associations and may be reassigned later, so unrelated messages are unremarkable. Do not enter them anywhere. If the code names a service you personally use, inspect that account as you would normally.

Ready to try SMSCode?

Create an account and get your first virtual number in under two minutes.

Get started →