The Code Read-Back Scam: Never Read a Verification Code Aloud
The call sounds perfectly professional: "This is the fraud department at your bank. We see unusual activity on your card. To verify you, we just sent a code to your phone. Read it back to me." The person on the line is not the bank. The code they want read back is the last lock on the account, and the moment your parent reads it aloud, the account is theirs. This page is the one rule that stops it, and what to do if the code was already shared.
codes are keys, and keys are never read aloud
The code read-back map
Two-factor protects accounts because a scammer with the password still cannot get in without the code. The read-back scam is the workaround: the parent is tricked into handing the key over while believing they are helping.
- The trickIt sounds like security, it is the attackA call from a spoofed trusted institution, a believable emergency ("fraud on your card"), and a request that sounds like verification: the parent is asked to help stop fraud, not to pay, which is what they are primed to refuse.
- The ruleCodes are only for you, typed by youA code is typed only when the parent asked for it, on the login screen. If anyone asks to read it aloud, text it back, or "confirm" it: hang up. It is always a scam. No real bank, company, or agency ever asks for the code.
- If a code was sharedThe account may be compromised right nowCall the real bank on the number on the back of the card immediately and say a verification code was shared; change the password if still possible (email first), check the recovery options for tampering, and report at reportfraud.ftc.gov.
- Prevent the nextOne short rule beats any explanation"Codes are never read aloud, to anyone, ever." Keep two-factor on (the scam abuses it, but accounts are safer with it), and the family rule: a "bank" that asks for a code means hang up and call the family or the card number.
The rule, in one sentence: a verification code is a key, and keys are never read aloud to anyone. No real bank, company, or agency will ever ask for the code over the phone, by text, or by email. The instant anyone asks for it, the call is the scam.
Why this scam is so effective
The code read-back scam combines every element that works on older adults: a call that appears to come from a trusted institution (caller ID can be spoofed), a believable emergency ("fraud on your card"), and a request that sounds like security ("to verify it's really you"). The parent is not being asked for money, which is what they are primed to refuse; they are being asked to help stop fraud, which is what they want to do. That is the trick. The "verification" is the attack.
What is actually happening
Two-factor authentication protects accounts because a scammer who has the password still cannot get in without the code. The code read-back scam is the workaround: instead of breaking the code, the scammer tricks the account owner into handing it over. When the parent reads the code aloud, the scammer uses it immediately to reset the password, change the recovery options, and take over the account, all while the parent believes they were helping.
The rule to teach your parent (print this)
What to do if a code was already shared
The account may be compromised right now, and the order matters:
- Call the real bank or company immediately using the number on the back of the card or the official website, not any number the caller gave. Tell them a verification code was shared with a scammer; they can lock the account and reverse the reset.
- Change the password on that account if you can still get in, and change it on any other account that uses the same password, starting with email.
- Check the recovery options: if the scammer already changed the recovery phone or email, say so when you call; that is the signature of a takeover. See Your parent's account was hacked: the 60-minute response for the full sequence.
- Report the call at reportfraud.ftc.gov.
Prevent the next one
- Teach the one rule and repeat it: "codes are never read aloud, to anyone, ever." It is shorter and stickier than any explanation of phishing.
- Keep two-factor authentication on (see Two-factor authentication for parents). The scam works by abusing it, but the accounts are still safer with it than without.
- Set the family rule: if a "bank" calls and asks for a code, the parent hangs up and calls you, or calls the number on the card. One sentence, printed, beats any filter.
- Use the scam-risk tool: paste a suspicious text or describe the call in Scam Risk Check before acting on it.
Related
- Two-factor authentication for parents: the protection this scam tries to defeat.
- How to verify any message independently: the call-back method that ends these calls.
- Impersonation scams: the full costume wardrobe of the "bank" on the line.
- Your parent's account was hacked: if the code was already used.
Sources
- FTC: How To Avoid a Scam (retrieved August 2026)
- FTC: Phone Scams (retrieved August 2026)
Found an error? Report it.