OTP Bot One-Time-Code Scams via Phone Calls
Automated OTP bots and live vishing agents place spoofed calls posing as your bank's fraud line, then walk you through reading out or keying in the one-time code that authorises the scammer's own login or payment.
Part of: OTP Bot & One-Time-Passcode Interception Scams
Last reviewed: 24 July 2026
The phone call is where the OTP bot scam does its real work, because a voice can do what a text cannot: sound calm, official, and urgent all at once while steering you second by second. The call is timed to land just as a genuine code hits your phone, and the caller ID is spoofed to show your bank's real name or number. What follows is either a polished automated voice that mimics a bank's IVR, or a live "fraud agent," each with one goal — to get the freshly arrived code out of your hands before you hang up. The distinction that matters most: the machine sending the code already knows it; only the caller needs you to say it aloud.
How this scam works on phone calls
The call arrives seconds after a real one-time code lands, with caller ID spoofed to show your bank's name or the number printed on your card. An automated voice — deliberately built to sound like a bank's IVR — announces "suspicious activity" or a payment you didn't make, then offers menu prompts: "press 1 to speak to our fraud team" or "to verify your identity, enter the six-digit code we've just sent using your keypad." Keying the code in is captured as DTMF tones and relayed to the waiting attacker in real time; reading it aloud works just as well for a live agent.\n\nMore advanced setups chain several codes in one call, walking you through a login, then a "new device confirmation," then a payment approval, each framed as another verification step. The script keeps you on the line — "don't hang up, the request expires in sixty seconds" — so you can't pause and call back. Some use a callback trap instead: a voicemail or text tells you to phone the "fraud line," and the number they give routes straight to the bot. The same call may also ask you to key in your card number, PIN, or date of birth.
Common red flags
- A code arrives and the phone rings about it within seconds — even showing your bank's real name or number
- An automated voice that sounds like a bank IVR asks you to enter or read back a one-time code
- A keypad prompt to 'enter the code to verify your identity' or to 'cancel' a transaction
- Being told not to hang up, or that the code expires in a set number of seconds
- The caller asks you to key in your card number, PIN, or date of birth using the keypad
- A voicemail or text telling you to call a 'fraud line' number they supply
- The action the code authorises — a login, new payee, or payment — is not one you started
How to protect yourself
- Never read out or key a one-time code into any call — no genuine bank or service ever asks you to confirm a code back to them
- Treat the caller ID as meaningless; a real bank name or number on screen can be spoofed exactly
- Hang up and call your bank back on the number printed on your card or in its official app, never a number given on the call or in a voicemail
- Read the code's own text in full — it names the action and warns you never to share the code — instead of trusting the caller's summary
- Ignore pressure to 'stay on the line'; ending the call costs a real agent nothing and defeats the scam
- Switch high-value accounts to an authenticator app or hardware key so there is no spoken code to intercept
How to report it
- Hang up, then call your bank or the real service on their official number to freeze the account and halt or reverse any pending payment
- Report the spoofed call to your national fraud service (in the US the FTC at reportfraud.ftc.gov and the FCC; in the UK Action Fraud and forward suspect texts to 7726)
- Report the spoofed number and any callback number to your phone carrier so they can trace and block it
- Note the caller's displayed number and name, the call time and length, and the exact timestamps of the code texts as evidence
- Warn your bank specifically that an OTP interception attempt occurred so they can review recent logins, new payees, and device enrolments
Frequently asked questions
The caller ID showed my bank's real number — doesn't that prove the call is genuine?
No. Caller-ID spoofing lets a scammer display any name or number they choose, including the exact one printed on your bank card. Phone networks pass along whatever the caller claims, so the display is not proof of anything. This is why the safe move is always to hang up and dial your bank yourself on a number you sourced independently — from your card or the official app — rather than trusting the number that rang you.
Is it safer to enter the code on the keypad than to say it aloud?
No — both hand the scammer the code. When you key digits during a call, they travel as DTMF tones that an OTP bot captures and relays to the attacker in real time, exactly as if you had spoken them. There is no version of giving a code to an inbound caller that is safe, because a genuine bank never needs you to confirm a code back to them in the first place. The keypad prompt is designed to feel more official, nothing more.
They told me not to hang up because fraud was happening 'right now' — what should I do?
Hang up anyway. The insistence that you stay on the line is the scam protecting itself: the moment you end the call and phone your bank independently, the scammer loses their window to extract the next code. A real fraud team is happy for you to call them back on your card's official number to confirm anything. Any genuine block on your account will still be there in a minute; the scammer's login attempt will not.