The Code Read-Back Scam: Never Read a Verification Code Aloud

The call sounds perfectly professional: "This is the fraud department at your bank. We see unusual activity on your card. To verify you, we just sent a code to your phone. Read it back to me." The person on the line is not the bank. The code they want read back is the last lock on the account, and the moment your parent reads it aloud, the account is theirs. This page is the one rule that stops it, and what to do if the code was already shared.

Last reviewed August 2026 Reading time: 5 minutes

codes are keys, and keys are never read aloud

The code read-back map

Two-factor protects accounts because a scammer with the password still cannot get in without the code. The read-back scam is the workaround: the parent is tricked into handing the key over while believing they are helping.

  1. The trickIt sounds like security, it is the attackA call from a spoofed trusted institution, a believable emergency ("fraud on your card"), and a request that sounds like verification: the parent is asked to help stop fraud, not to pay, which is what they are primed to refuse.
  2. The ruleCodes are only for you, typed by youA code is typed only when the parent asked for it, on the login screen. If anyone asks to read it aloud, text it back, or "confirm" it: hang up. It is always a scam. No real bank, company, or agency ever asks for the code.
  3. If a code was sharedThe account may be compromised right nowCall the real bank on the number on the back of the card immediately and say a verification code was shared; change the password if still possible (email first), check the recovery options for tampering, and report at reportfraud.ftc.gov.
  4. Prevent the nextOne short rule beats any explanation"Codes are never read aloud, to anyone, ever." Keep two-factor on (the scam abuses it, but accounts are safer with it), and the family rule: a "bank" that asks for a code means hang up and call the family or the card number.

The rule, in one sentence: a verification code is a key, and keys are never read aloud to anyone. No real bank, company, or agency will ever ask for the code over the phone, by text, or by email. The instant anyone asks for it, the call is the scam.

Why this scam is so effective

The code read-back scam combines every element that works on older adults: a call that appears to come from a trusted institution (caller ID can be spoofed), a believable emergency ("fraud on your card"), and a request that sounds like security ("to verify it's really you"). The parent is not being asked for money, which is what they are primed to refuse; they are being asked to help stop fraud, which is what they want to do. That is the trick. The "verification" is the attack.

What is actually happening

Two-factor authentication protects accounts because a scammer who has the password still cannot get in without the code. The code read-back scam is the workaround: instead of breaking the code, the scammer tricks the account owner into handing it over. When the parent reads the code aloud, the scammer uses it immediately to reset the password, change the recovery options, and take over the account, all while the parent believes they were helping.

The rule to teach your parent (print this)

Codes and you: 1. A code is only for YOU. You type it in yourself. 2. You type it only when YOU asked for it, on the login screen. 3. If anyone asks you to read a code out loud, or text it back, or "confirm" it: HANG UP. It is always a scam. 4. No real bank, company, or agency ever asks for your code. 5. If you already read one out: call the real number on your card, right away, and tell them.

What to do if a code was already shared

The account may be compromised right now, and the order matters:

  • Call the real bank or company immediately using the number on the back of the card or the official website, not any number the caller gave. Tell them a verification code was shared with a scammer; they can lock the account and reverse the reset.
  • Change the password on that account if you can still get in, and change it on any other account that uses the same password, starting with email.
  • Check the recovery options: if the scammer already changed the recovery phone or email, say so when you call; that is the signature of a takeover. See Your parent's account was hacked: the 60-minute response for the full sequence.
  • Report the call at reportfraud.ftc.gov.

Prevent the next one

  • Teach the one rule and repeat it: "codes are never read aloud, to anyone, ever." It is shorter and stickier than any explanation of phishing.
  • Keep two-factor authentication on (see Two-factor authentication for parents). The scam works by abusing it, but the accounts are still safer with it than without.
  • Set the family rule: if a "bank" calls and asks for a code, the parent hangs up and calls you, or calls the number on the card. One sentence, printed, beats any filter.
  • Use the scam-risk tool: paste a suspicious text or describe the call in Scam Risk Check before acting on it.

Related

Sources

Found an error? Report it.