Is a two-factor authentication code request I didn't trigger a sign I am being hacked?
Yes — receiving an unexpected 2FA code means someone has your username and password and is actively trying to log in to your account. Change your password immediately.
Last reviewed: 1 August 2026
Explanation
When you receive a two-factor authentication (2FA) code you did not request, it means someone else has your password and has entered it on the login page — triggering the code that is now in your inbox or on your phone. The 2FA system is working as intended by stopping them at the second step, but your password is compromised. You should change your password immediately on that account and on any other service where you use the same password. Do not share the 2FA code with anyone — if someone calls or messages you asking for it, they are a scammer trying to complete the login they triggered. Enable a stronger second factor such as an authenticator app rather than SMS where the service allows it.
Think about where the password came from. Most often it was exposed in a data breach of some other service and reused, or it was captured by a phishing page. Either way, the code you received is evidence that the credential is circulating and being tried — so treat the event as a prompt to clean up password reuse generally, not just on the one account.
The follow-up contact is the most dangerous part. Fraudsters who trigger a code will sometimes call or text posing as the company's security team and ask you to 'confirm' the code to block the attempt. Reading it out completes their login. No legitimate service will ever ask you to repeat a security code to a person.
Common red flags
- You receive a 2FA SMS code without having tried to log in
- You receive multiple codes in succession, suggesting repeated login attempts
- Shortly after the code arrives, someone contacts you asking for it
- You are unable to log in to your account — it may already be taken over
What to do now
- Change your password immediately using a device you trust
- Change the same password on every other site where you used it
- Do not share the 2FA code with anyone who contacts you about it
- Review recent account activity and check for any changes you did not make
Frequently asked questions
If I have 2FA enabled, is my account safe even if my password is stolen?
2FA significantly raises the difficulty for attackers, but it is not infallible. Real-time phishing sites can relay your 2FA code before it expires. Changing your password promptly eliminates the stolen credential.
Should I be worried if I only received one code and nothing else happened?
A single code still means your password was entered by someone else. It may have been an automated attempt using breached credentials. Change the password anyway — the attempt failing this time does not mean the credential is safe.