OTP Bot & One-Time-Passcode Interception Scams
Automated bots place spoofed calls or texts posing as your bank's anti-fraud line and trick you into reading out a one-time passcode — the very code the scammer just triggered by logging into your account, instantly defeating two-factor authentication.
Last reviewed: 24 July 2026
What this scam is
An OTP bot scam is a method for defeating two-factor authentication by getting you to hand over the one-time passcode yourself. Two-factor login and payment approvals rely on a short code — sent by text, email, authenticator app, or automated call — that only the real account holder should ever see. The scammer already has your username and password (from a breach, phishing, or a purchase on a criminal marketplace), but the code stops them. So they trigger it, then call or text you to extract it. The "bot" is automated software, frequently sold and rented through Telegram channels, that places convincing spoofed calls or messages impersonating your bank, card provider, or a service like a payment app, email provider, or exchange. It reads a natural-sounding anti-fraud script, prompts you to "verify" by entering or reading back the code that just arrived, and relays whatever you provide to the waiting attacker in real time. The distinction that matters most: the code authorises an action the scammer initiated, not one you did.
How it works
The sequence is tightly choreographed around a few seconds. Having obtained your login details, the attacker enters them on the real service — your bank, email, or a payment app — which triggers a genuine one-time passcode sent to your own phone. At almost the same instant, the OTP bot contacts you. A spoofed call shows your bank's real name or number, and an automated, professional voice warns of "suspicious activity" or a payment you didn't make, then says it must "verify your identity" before blocking it. It instructs you to key in or read out the code you've just received. Because the text genuinely came from your bank moments earlier, the timing feels like proof the call is real. The bot captures the digits and relays them to the attacker, who types them into the live login or payment screen, completing the takeover before the call ends. More advanced bots handle several codes in one session — chaining a login, a device enrolment, and a payment approval — and can prompt for card numbers, PINs, or your date of birth using the same trusted-sounding script.
Why this scam works
This scam inverts the psychology of security. Codes are framed by legitimate services as a protection you must guard, so a caller who claims to be checking that protection sounds like an ally, not an attacker. Three cues stack to disarm you: caller-ID spoofing that displays a real bank name or number, a text you can see actually arrived, and the urgency of fraud you're told is happening right now. Fear of losing your money overrides the instinct to slow down. Automation makes it worse — a bot sounds like the polished IVR systems banks really use, runs the same reliable script against thousands of people, and never fumbles. Crucially, most people don't hold the one rule that defeats it: a code proves identity to the machine, so anyone who phones asking for it is, by definition, trying to be you.
Common red flags
- An unexpected one-time code arrives, immediately followed by a call or text about it
- A caller — even one showing your bank's real name or number — asks you to read back or enter a code
- Pressure that fraud is happening 'right now' and the code is needed to block it
- The message or call asks you to confirm the code to 'verify' or 'cancel' a transaction
- The action the code authorises (a login, new payee, or payment) is not one you started
- An automated voice that sounds like a bank IVR but asks for codes, PINs, card numbers, or your date of birth
- Being told not to hang up or to stay on the line while you 'confirm' details
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
This is the fraud prevention line for your bank. We've detected a £940 payment to a new payee. To block it, please enter the six-digit code we've just sent to your phone.
Your account security code is 284915. We will never call to ask for this code. If you did not request it, do not share it with anyone.
Verizon Security: someone is attempting to sign in to your account from a new device. Reply with the verification code to stop this login.
To confirm this is really you and cancel the transfer, read me the code you just received. Do not end the call — the request expires in 60 seconds.
How to verify before you act
Treat any inbound contact about your account as unverified, no matter what the caller ID shows — spoofing makes the displayed name and number worthless as proof. Never read out, type into a keypad, or forward a one-time code to anyone who contacted you; legitimate banks, card providers, government bodies, and services never ask you to confirm a code back to them, because on their side the code has already done its job. Read the text itself, not the caller's summary of it: genuine security messages usually say plainly "we will never ask you for this code" and often name the exact action being authorised — a login, a new payee, a payment amount. If that action isn't one you started, someone else did. Hang up, then reach your bank independently using the number printed on your card or its official app or website, and ask whether any contact was real. The pause costs a genuine agent nothing and costs the scammer everything.
Payment methods used
- Bank transfer
- Payment apps
- Cryptocurrency
- Gift cards
Who is usually targeted
- Online banking customers
- Payment-app and wallet users
- Cryptocurrency holders
What to do immediately
- Stop the call immediately and do not share any further codes or details
- Change the password on the targeted account, and on any other account sharing that password, from a device you trust
- Contact your bank or the real service directly using their official number or app to freeze accounts and reverse or halt any pending payments
- Ask the service to review recent logins, new payees, device enrolments, and any changed contact details, and remove anything you don't recognise
- Where possible, switch that account's two-factor method to an authenticator app or hardware key instead of SMS
- Report the fraud to your national fraud service and warn your bank that an OTP interception attempt occurred
How to prevent it
- Never read out, key in, or forward a one-time passcode to anyone who called or messaged you — no legitimate agent ever asks you to
- Treat caller ID and sender names as unverifiable; a real bank name on screen can be spoofed
- Always read the code's text in full — it will name the action and warn you never to share the code
- If the action the code authorises isn't one you started, assume your password is compromised and change it
- Hang up and call your bank back on the number from your card or its official app, never a number the caller gives you
- Prefer app-based approvals or a hardware security key over SMS codes, and enable transaction alerts on your accounts
Evidence to preserve
- The one-time-code texts or emails, showing their exact timestamps
- The caller's number, displayed name, and the time and length of the call
- Any follow-up messages, and screenshots of unrecognised logins, new payees, or account changes
- Bank or payment-app records of any transactions the scammer authorised
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
Why would my bank send me a real code and then a scammer call about it?
Because the scammer caused the code to be sent. They already have your username and password and are trying to log in or approve a payment on the real system, which makes your bank genuinely text you a code. The call arrives seconds later precisely because the code is fresh in your hands. The text is real; the caller is not. That uncomfortable pairing — a legitimate code and an urgent call about it — is the signature of this scam, not evidence the call is genuine.
Will a real bank or service ever ask me to read back a one-time code?
No. This is the single rule that defeats the entire scam. A one-time code proves your identity to the service's own systems, so on their side the code has already done its work — they have no reason to ask you for it. Banks, card providers, payment apps, email providers, and government bodies across the US, UK, and Australia all say the same thing, and their own code messages usually spell it out. Anyone who phones, texts, or emails asking you to confirm a code is trying to become you.
Are these calls really run by automated bots?
Often, yes. Criminals sell and rent OTP bots through channels on platforms like Telegram, letting even unskilled fraudsters place spoofed calls or texts at scale. The bot delivers a polished, IVR-style script, captures whatever code you provide, and relays it to the attacker instantly — sometimes handling several codes in one call to chain a login, a device enrolment, and a payment. Automation is why the voice sounds so professional and the timing so precise, but the defence is unchanged: never share a code with anyone who contacted you.