Why you're suddenly getting 2FA codes you didn't request
Your phone buzzes. "Your verification code is 1994. Never share this code with anyone." A few minutes later another one lands from a different company. Then a third.
You aren't trying to log in anywhere. So what is this?
Someone has a working password for one of your accounts and tried to use it. Two-factor authentication stopped them at the door, which is why the code came to you instead of to them. The good news is that the block held. The bad news is that your password is in someone else's hands, and they know which accounts to point it at.
What is actually happening
A burst of unrequested codes is the visible end of an automated attack called credential stuffing.
It works in four steps:
- A breach somewhere else. Attackers buy a database of email addresses and passwords leaked from a company that has nothing to do with the app now texting you.
- Automated replay. Bots test those pairs against hundreds of popular sites at machine speed, betting that people reuse passwords. That bet is usually right.
- A hit. On sites where your password still works, the login gets to the second step.
- The block. Two-factor authentication pauses the login and sends the code to your phone. The attacker sits on the other side of a door they can't open.
Codes from several services inside a few minutes is the signature. It means one email-and-password pair is being replayed across a list, not that four separate companies were breached tonight.
There's a variant worth recognizing. If codes or push prompts arrive over and over for hours, that's MFA fatigue: the volume is the point. The attacker wants you tired enough to approve one prompt to make it stop, or distracted enough to miss a real password-reset warning buried in the pile.
What to do in the next 10 minutes
Don't share the code, and don't approve the prompt. No company will ever call, text, or email asking you to read back a verification code. Anyone who does is the person waiting on the other side of that login. If a caller claims to be from fraud prevention and needs the code to verify you, hang up and call the number printed on your card.
Change the password, from the app, not the text. Don't tap links in the message. Open the official app or type the address yourself, then change the password. Make it unique to that account and store it in a password manager, because the whole attack depends on one password opening more than one door.
Change it everywhere you reused it. This is the step people skip, and it's the one that matters. If that password guarded your email as well, start there. Whoever controls your email can reset everything else.
Move off SMS where you can. Text-message codes are the weakest second factor, because they can be intercepted through a SIM swap. An authenticator app generates codes on the device in your hand, so there's nothing in transit to steal. Passkeys and hardware keys are stronger still.
Check what the account did while you weren't looking. Recent logins, new devices, changed recovery email or phone, saved payment methods. On financial apps, check transfers and linked accounts.
Why they found you
Stolen passwords are cheap and plentiful. What makes them dangerous is context.
A password alone is a string. A password attached to your current phone number, your email address, your home address, and the names of your relatives is an identity. That combination is what lets someone answer a security question, pass a customer-service check, or write a phishing text convincing enough that you tap the link.
Attackers don't have to breach anything to get that context. Data brokers and people-search sites collect it from public records, purchase histories, and app trackers, then publish and sell it openly. Your phone number sitting on a people-search profile next to your name and street address is what turns a years-old leaked password into a targeted attempt.
Your information doesn't need to be hacked to be used against you. It only needs to be findable.
What removing your data changes
You can't retract a password that already leaked, and nobody can pull data back off the dark web. What you can change is the open-web half of the equation: the broker profiles and people-search listings that keep your current contact details attached to your name.
Delist finds those listings, files the opt-outs, and keeps checking, because brokers routinely repopulate a profile weeks after a removal goes through. Fewer live listings means less material for building a targeted attempt against you, and fewer places for the next attacker to start.
Start with a free scan to see which sites are currently publishing your details.
Frequently asked questions
Does getting a 2FA code mean I was hacked?
No. It means someone had a working password and the second factor stopped them. They don't have access. They do have your password, so change it now, and change it anywhere you reused it.
Can I just ignore the code?
Ignoring it blocks today's attempt and leaves the underlying problem in place. The attacker knows the password works. If they later intercept your texts through a SIM swap, or get into the email account behind the service, the second factor stops helping.
Why am I getting codes from several apps at once?
Because one email-and-password pair is being replayed across a list of sites by a bot. Every site where that password still works fires a code. It's one attack, not several.
Someone called about the code. Should I read it to them?
No. That call is the attack. The code is the only thing standing between an attacker and your account, and a legitimate company never needs you to recite it. Hang up and call back on a number you looked up yourself.
I use an authenticator app. Why did I still get a text?
Some services fall back to SMS when a login comes from an unfamiliar device, and some accounts keep a phone number on file as a backup method even after you add an app. Check the account's security settings and remove SMS as a recovery option where the service allows it.
Will changing my password stop the codes?
For that account, usually yes, once the stored password stops working. Codes from other services will continue until you change the password there too, which is why the reused-password sweep matters more than any single reset.
More guides
Find out what data brokers know about you
A free scan shows which sites are exposing your name, phone, address and email, and Delist files the removals for you.