What to Do If You Gave a Scammer Your Password or Verification Code

 


Giving a scammer your password or verification code can be serious, but the right response depends on exactly what you shared and whether the scammer has already used it.

A password can let someone attempt to sign in.

A one-time verification code, authentication code, or login approval may let them complete a sign-in that would otherwise have been blocked.

That is why you should act quickly.

1. Stop Communicating With the Scammer

Do not continue the conversation.

Do not:

  • Send another code
  • Approve another login
  • Share screenshots
  • Share recovery codes
  • Give remote access
  • Send money
  • Follow more links

FTC guidance says anyone asking you for an account verification code is a scammer.

2. Use the Real Website or App

Do not go back through the scammer's link.

Open the legitimate website or app yourself.

For example, if the incident involved Google, Microsoft, Facebook, a bank, or another service, type the official address yourself or open the official app.

This helps prevent you from entering new credentials into another fake page.

3. Change the Password Immediately

If you gave away a password, change it as soon as possible.

Create a new password that is:

  • Unique
  • Strong
  • Not based on the old one
  • Not used on another account

FTC guidance specifically recommends creating a new strong password if you gave a scammer your username and password.

4. Change Reused Passwords Too

If the same password was used elsewhere, change those accounts too.

Attackers may try the stolen credentials on:

  • Email
  • Social media
  • Shopping sites
  • Cloud storage
  • Banking
  • Other services

Password reuse can turn one mistake into several account compromises.

If you are worried that your credentials may have been exposed in a breach, review what to do after a data breach.

5. Prioritize Your Email Account

If the compromised password was for your email account, secure it first.

Email is often used to reset passwords for other services.

Review:

  • Password
  • Recent sign-ins
  • Recovery email
  • Recovery phone
  • Forwarding rules
  • Connected apps
  • Unknown devices

If anything looks unfamiliar, remove it.

6. Review Recent Security Activity

For services that provide security history, check it immediately.

Look for:

  • Unknown logins
  • New devices
  • Password changes
  • Recovery-information changes
  • MFA changes
  • Security alerts you do not recognize

Google specifically recommends reviewing recent security events when you suspect compromise.

7. Sign Out Unknown Devices or Sessions

If the account lists active devices or sessions, remove anything unfamiliar.

Do not assume changing the password automatically invalidates every active session.

Review every device you can.

8. If You Shared a Verification Code

Treat the incident seriously.

A one-time code may have been used to complete a login.

Immediately:

  • Change the password
  • Review recent sign-ins
  • Remove unfamiliar devices
  • Check MFA settings
  • Review recovery information
  • Sign out suspicious sessions

FTC warns that verification codes are meant for you to prove your identity and should not be shared.

9. If You Approved a Login Prompt

Sometimes the second factor is not a code.

You may have tapped:

Yes, it's me

or approved a sign-in notification.

If you approved a request you did not initiate:

  • Change the password
  • Review security activity
  • Remove unfamiliar devices
  • Revoke unknown sessions
  • Strengthen MFA

An approval prompt can serve the same purpose as a verification code.

10. If You Shared a Recovery Code

Recovery codes can sometimes bypass ordinary second-factor checks.

If you shared one:

  • Change the password
  • Regenerate recovery codes if the service allows it
  • Invalidate old recovery codes
  • Review account recovery settings
  • Check recent sign-ins

Treat recovery codes like passwords.

11. Turn On Multi-Factor Authentication

If MFA was not already enabled, turn it on.

CISA recommends MFA because it adds another barrier beyond the password.

Where available, consider stronger phishing-resistant options such as:

  • Passkeys
  • Physical security keys

Google notes that passkeys are resistant to common phishing techniques because they cannot be copied or accidentally handed over like passwords.

12. Review Recovery Information

Check:

  • Recovery email
  • Recovery phone
  • Backup authentication methods
  • Recovery codes
  • Trusted devices

If a scammer changed recovery information, they may be able to regain access later.

Remove anything unfamiliar.

13. Review Connected Apps

Check third-party apps connected to the affected account.

Remove anything you:

  • Do not recognize
  • Did not authorize
  • No longer use

A compromised app connection can remain useful to an attacker even after a password change.

14. Check for Password-Reset Emails

Look for unexpected password-reset messages from other services.

A scammer who gained access to your email may try to reset other accounts.

Check:

  • Inbox
  • Spam
  • Trash
  • Deleted items

Unexpected reset messages are a warning sign.

15. Check Sent Mail and Account Changes

If the affected account is email, check:

  • Sent messages
  • Forwarding
  • Filters
  • Deleted mail
  • Security alerts

If someone sent messages from your account, warn affected contacts after you secure the account.

16. If You Used the Password on a Banking Account

Contact the bank through the official app, website, or phone number.

Do not use contact details sent by the scammer.

Review:

  • Recent transactions
  • Pending payments
  • New payees
  • Account changes

Act quickly if financial activity is involved.

17. If You Shared a Bank Verification Code

This is especially serious.

A bank verification code may allow a scammer to:

  • Complete a login
  • Add a payment method
  • Confirm a transfer
  • Change security settings

Contact the financial institution immediately using official contact information.

FTC warns that scammers may ask for verification codes while pretending to protect your money.

18. Never Move Money to “Protect It”

A scammer may claim your account is compromised and tell you to transfer money to a “safe” account.

Do not do it.

FTC warns that requests to move money to protect it are scams.

19. If You Paid the Scammer

Contact the bank, card issuer, or payment provider.

Explain that the payment was related to fraud.

Ask what options may be available.

Do not pay another person who promises to recover the money for an upfront fee.

20. Scan Your Device if You Clicked or Installed Something

Sometimes the password theft is only part of the incident.

If you also:

  • Opened a suspicious attachment
  • Installed software
  • Gave remote access
  • Downloaded a file

scan the device with trusted security software.

FTC guidance recommends updating legitimate security software and scanning the computer after tech-support scams.

21. Change Important Passwords From a Trusted Device

If you suspect malware or remote-access software on the affected computer, use another trusted device for important password changes when possible.

This reduces the chance that new credentials are captured again.

22. Watch for Follow-Up Scams

Once a scammer knows you responded, they may contact you again.

A second scammer may claim to be:

  • Your bank
  • Microsoft
  • Google
  • Police
  • A recovery company
  • A fraud department

Verify independently.

Do not trust someone simply because they know details from the first incident.

23. Be Careful With New MFA Prompts

After securing the account, watch for unexpected:

  • Login approvals
  • SMS codes
  • Authenticator prompts
  • Password-reset messages

Do not approve anything you did not initiate.

24. Consider Passkeys or Security Keys

If the service supports passkeys or hardware security keys, consider using them.

Phishing-resistant MFA can reduce the risk of a scammer stealing a password and second factor through a fake login page. CISA specifically promotes phishing-resistant MFA for stronger account protection.

25. A Quick Emergency Checklist

If you gave a scammer a password or code:

  • Stop communicating
  • Open the official website or app
  • Change the affected password
  • Change reused passwords
  • Review recent security activity
  • Sign out unknown devices
  • Check recovery information
  • Remove unfamiliar connected apps
  • Turn on MFA
  • Regenerate recovery codes if needed
  • Check email forwarding and filters
  • Review banking activity if financial information was involved
  • Contact the bank if a banking code was shared
  • Scan the device if suspicious software or links were involved
  • Watch for follow-up scams

26. What If Nothing Suspicious Has Happened Yet?

Do not assume that means everything is safe.

If you gave away a password or code, the scammer may not act immediately.

Secure the account anyway.

Early action can prevent later misuse.

Final Verdict

Giving a scammer your password or verification code can allow them to get much closer to taking over an account.

The most important steps are:

  • Change the password
  • Review recent activity
  • Remove unfamiliar devices
  • Secure recovery information
  • Turn on MFA
  • Protect other accounts that reused the same password

If a bank account or financial verification code was involved, contact the financial institution immediately.

Most importantly, never share one-time verification codes, recovery codes, or unexpected login approvals with another person.

Guide note: This article reflects FTC, Google, and CISA security guidance available in August 2026. Account-recovery menus and authentication options can change over time, so always use the current official support guidance for the specific service involved.

Comments

Popular posts from this blog

VirusTotal Review: Can It Help You Check Suspicious Links and Files?

Complete Guide to Staying Safe Online: Websites, Apps, Offers, Payments and Privacy

How to Choose Safe and Useful Online Offers: A Beginner’s Guide