{"id":8732,"date":"2023-09-01T14:02:49","date_gmt":"2023-09-01T18:02:49","guid":{"rendered":"https:\/\/tcn.tidbits.com\/?p=10026"},"modified":"2023-09-01T15:44:11","modified_gmt":"2023-09-01T19:44:11","slug":"what-should-you-do-about-an-authentication-code-you-didnt-request","status":"publish","type":"post","link":"https:\/\/www.macworks.com\/blog\/what-should-you-do-about-an-authentication-code-you-didnt-request\/","title":{"rendered":"What Should You Do about an Authentication Code You DIDN\u2019T Request?"},"content":{"rendered":"<p>We strongly encourage using two-factor authentication (2FA) or two-step verification (2SV) with online accounts whenever possible. The details vary slightly, but with either one, after you enter your password, you must enter an authentication code to complete the login. Although it\u2019s always best to get such codes from an authentication app like <a href=\"https:\/\/1password.com\/\" target=\"_blank\" rel=\"noopener\">1Password<\/a> (which enters codes for you), <a href=\"https:\/\/authy.com\/\" target=\"_blank\" rel=\"noopener\">Authy<\/a>, or <a href=\"https:\/\/apps.apple.com\/us\/app\/google-authenticator\/id388497605\" target=\"_blank\" rel=\"noopener\">Google Authenticator<\/a>, many websites still send codes by the less secure SMS text message or email. They\u2019re better than nothing.<\/p>\n<p>But what if you receive a 2FA code that you didn\u2019t request?<\/p>\n<ol>\n<li>Don\u2019t panic. Although receiving the code means that someone is trying to log in to your account and has your password, the extra authentication step has done its job and protected your account from being compromised.<\/li>\n<li>Never share an authentication code with anyone! A hacker could attempt to break into your account, be foiled by two-factor authentication, and then email or text you with a trumped-up story about why you should send them the code. Authentication codes are short-lived, so if this is going to happen, it will happen right away.<\/li>\n<li>Independently from the message with the code, go to the account website, log in, and change the password. As always, make sure the password is strong, unique, and stored in your password manager. If the account used an old password that was shared with other accounts, change passwords on those accounts as well.<\/li>\n<\/ol>\n<p>There are a handful of scenarios that could generate such an authentication code:<\/p>\n<ul>\n<li><b>Stolen credentials:<\/b> The most likely scenario, which the advice above addresses, is when your email address and password have been stolen, probably in a significant site breach. You can check the <a href=\"https:\/\/haveibeenpwned.com\/\" target=\"_blank\" rel=\"noopener\">Have I Been Pwned<\/a> site to see if your account is floating around on the \u201cdark Web.\u201d Password managers often perform similar checks. Changing the password on any breached sites is essential.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"wp-image-10010 alignnone\" src=\"https:\/\/macworks.com\/blog\/wp-content\/uploads\/2023\/09\/what-should-you-do-about-an-authentication-code-you-didnt-request-1.jpg\" alt=\"\" width=\"695\" height=\"411\" \/><\/li>\n<li><b>Identity theft:<\/b> You started receiving authentication codes from TikTok, but you don\u2019t remember creating a TikTok account. Someone might be trying to create an account to impersonate you but cannot complete the account creation without the authentication code. There isn\u2019t much you can do to stop such attempts, although if an account has been created, you should be able to change the password (since it\u2019s using your email address or phone number), log in, and either just let the account sit in your password manager or try to delete it.<\/li>\n<li><b>Accidental or random triggering:<\/b> If you have a common email address or phone number, someone could have accidentally entered your address or number instead of theirs while trying to create an account. It\u2019s easy to type <a href=\"mailto:marsha32@example.com\" target=\"_blank\" rel=\"noopener\">marsha32@example.com<\/a> instead of <a href=\"mailto:marsha23@example.com\" target=\"_blank\" rel=\"noopener\">marsha23@example.com<\/a> or mistake the Boston 617 area code for the upstate New York 607 area code. If you\u2019re sure you don\u2019t have an account at the site in question and you only get one authentication code, you can probably ignore it.<\/li>\n<\/ul>\n<p>Regardless of the cause, don\u2019t ignore 2FA codes you didn\u2019t request for sites where you have an account. It\u2019s not hard to change a password, particularly if you use a password manager, and the extra piece of mind is worth the few minutes of work.<\/p>\n<p>(Featured image based on an original by iStock.com\/Kateryna Onyshchuk)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We strongly encourage using two-factor authentication (2FA) or two-step verification (2SV) with online accounts whenever possible. The details vary slightly, but with either one, after you enter your password, you must enter an authentication code to complete the login. Although it\u2019s always best to get such codes from an authentication app like 1Password (which enters [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":8733,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9,69,106,112,185,104],"tags":[],"class_list":["post-8732","post","type-post","status-publish","format-standard","has-post-thumbnail","category-apple","category-apple-consulting-ct","category-apple-support-ct","category-mac-support-ct","category-mactech","category-security"],"_links":{"self":[{"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/posts\/8732","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/comments?post=8732"}],"version-history":[{"count":1,"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/posts\/8732\/revisions"}],"predecessor-version":[{"id":8738,"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/posts\/8732\/revisions\/8738"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/media\/8733"}],"wp:attachment":[{"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/media?parent=8732"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/categories?post=8732"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.macworks.com\/blog\/wp-json\/wp\/v2\/tags?post=8732"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}