Two-factor authentication helps only when you treat the second factor like a private house key, not like a routine code to share.

FTC guidance on verification-code scams is blunt: anyone who asks for your verification code is a scammer. The code is for you to type into your own login screen, not to read aloud, text back, or copy into a chat.

Level 2 is about the messy case: the caller already knows your name, bank, or partial account details and sounds helpful. That does not make the request safe.

A quick example: someone claiming to be your bank says they found fraud and need the code they just texted you so they can “verify” you. In reality, they are trying to log in as you.

Cross-level note: Level 1 introduced 2FA as a safety tool. Level 2 teaches the stronger skill: spotting when the tool itself is being turned against you.

What to do:

  • Never share a verification code with a caller, texter, or email sender.
  • If you are worried, hang up and sign in through the official app or site yourself.
  • Treat unexpected 2FA prompts as a sign to check your account calmly.

This lesson is part of Email & Online Accounts from Lumoset Foundation, Fort Wayne, Indiana – free, always, with no account and no catch.