OTP & MFA Safety

    Your OTP. Your Eyes Only.

    Keep verification codes private, reject approval prompts you did not start, and report them.

    Everyday Cyber SafetyEveryday usersIT & help deskLeadership

    Illustrative scenario

    How It Looks in Real Life

    Late at night your phone shows repeated “Approve sign-in?” prompts. A message then arrives from “IT Support” saying the prompts will stop once you tap Approve.

    Understand it

    How the Attack Works

    One-time codes and approval prompts prove that you are the person signing in. If someone already has your password, the code or approval is the last barrier, so attackers try to talk you into handing it over or tapping Approve.

    Red flags

    Warning Signs

    • Anyone asking you to read out or forward a verification code.
    • A code arriving when you are not signing in anywhere.
    • Repeated approval prompts, often at unusual hours.
    • Pressure to approve “to stop the alerts” or “to secure the account”.

    Safer habits

    What to Do Instead

    • 1Only approve prompts you started yourself, seconds earlier.
    • 2Deny unexpected prompts and report them; they usually mean your password is known.
    • 3Use number-matching or phishing-resistant methods such as passkeys where offered.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: entered credentials or shared a code
    1. 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
    2. 2Change the password from a trusted device by typing the real address yourself.
    3. 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
    4. 4Review recovery email, phone number and forwarding rules for unexpected changes.
    If you: approved app permissions or a sign-in request
    1. 1Report it straight away so IT can revoke the session or app consent.
    2. 2Remove the unfamiliar app from your account’s connected apps or permissions page.
    3. 3Changing your password does not remove app permissions or tokens already issued.

    Knowledge Check

    What Would You Do?

    A caller from your “bank fraud team” says they sent you a code to verify your identity and asks you to read it back. What do you do?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us