Two-factor authentication bypass
In plain terms
The scammer already has your password and triggers a login. They call you right afterward to get you to read out the code you received — or flood you with approval requests until you accept one.
Definition
Bypassing two-factor authentication targets the second factor itself: instead of breaking through it technically, the attacker gets the victim to hand it over or approve it.
How it works
The attacker already has the password and triggers a login, which sends a code or a notification to the victim. They then act along one of two paths. In the first, they call or message within the following seconds, posing as the service in question, and ask the victim to share "the verification code" — the code is genuine, which makes the request credible. In the second, they send dozens of approval requests until the victim, worn down or woken at night, accepts one just to stop the notifications. In both cases the protection works as designed: it's consent that's obtained, not the mechanism that's broken.
Warning signs
- A verification code received without having tried to log in
- Repeated approval requests, in a burst or during the night
- A caller asking you to read them a code, whatever the stated reason
- A message urging you to "approve to cancel" a suspicious login
- Contact arriving immediately after the code is received
How to verify
A code received that you didn't trigger means one thing: someone already knows your password. That's the signal to change it immediately. No service, no bank, no support line ever asks you to share a verification code, whatever the channel.
What to do
Never share a code and refuse any approval request you didn't initiate yourself, the second it arrives. Then change the password of the affected account. Prefer an authenticator app or a physical security key over an SMS code.
If it already happened
Change the password, revoke all active sessions, and check the account's recovery settings — backup address, phone number, forwarding rules — which the attacker changes first to keep access. Regenerate backup codes.
Frequently asked questions
- Is two-factor authentication still worth anything?
- Yes, and it remains essential: it's precisely because it blocks the attacker that they have to ask for your help to get past it. A physical security key or an authenticator app resists far better than an SMS code.
- I approved a notification by mistake — what should I do?
- Change the password immediately, then sign out of all active sessions in the account settings. Then check the recovery address and the email's forwarding rules: these are the first things changed after an intrusion.
Related attacks
Official sources
This article is part of the Credentials and accounts family. Last updated: 2026-08-31.