What OTP, 2FA & Authentication Codes covers
This section covers one-time PINs, two-factor authentication and authenticator apps — the codes that arrive by SMS or appear in an app when you log in, pay for something or change an account detail.
Everything here rests on one rule, and it is worth stating before anything else.
Nobody legitimate will ever ask you for a one-time code. Not your bank. Not SASSA. Not your mobile network. Not a courier, an employer, a colleague, or anyone from a “fraud department”. A request for your code is the fraud, without exception.
The reason is simple once you see it. A one-time PIN exists to prove that the person completing an action is you. It is generated for your session and sent to you. An organisation that sent you the code already knows it and has no reason to ask. Someone who needs it from you is someone trying to complete an action on your account.
The second thing worth understanding is why an authenticator app is stronger than an SMS. Codes sent by text depend on your phone number, and a phone number can be transferred to a criminal through a SIM swap. Authenticator codes are generated on your device from a shared secret and never travel over the network, so a SIM swap does not reach them.
Browse individual used-for guides
Most searched questions in this topic
How the guides in this section differ
Delivery method. SMS codes, authenticator apps, push approvals and hardware keys all do the same job with meaningfully different security. The order of strength is roughly: hardware key, then authenticator app, then push, then SMS. Any of them is far better than none.
One-time code or standing PIN. An OTP is generated per action and expires within minutes. A banking or card PIN is a standing secret. Both should never be shared, but they behave differently and are covered separately.
Service-specific codes. SASSA and mobile network codes attract particular search interest in South Africa, largely because they are so heavily targeted by impersonation scams.
| Method | Strength | Weakness |
|---|---|---|
| Hardware security key | Strongest | Cost; can be lost |
| Authenticator app | Strong; resists SIM swap | Losing the phone without backup codes |
| Push approval | Good | Approving out of habit without reading |
| SMS one-time PIN | Better than nothing | SIM swap, message interception |
| No second factor | Password alone | A leaked password is enough |
Related topics and alternatives
- Explore CAPTCHA, Bot Checks & Human Verification
- Explore Security & Verification Basics
- Explore Security, Privacy & Access Tools
Safety, accuracy and next-step checks
These guides follow official service-provider and cyber-safety guidance. They will never ask you to enter, forward or confirm a code.
Points worth carrying:
- Never share a code with anyone, including someone who knows your name, ID number and account details. Criminals frequently have those already, and use them to sound credible.
- An unexpected code means someone has your password. Do not enter or forward it. Change that account’s password and switch on two-factor authentication if it is not already active.
- Contact organisations yourself using a number from your card, your statement or the official website — never a number from the message that alarmed you.
- Treat urgency as a warning sign. Pressure to act immediately is a technique, not a coincidence.
- Report a suspected SIM swap immediately to your mobile provider and to your bank. Losing signal unexpectedly, especially alongside account alerts, is a classic sign.
- Move to an authenticator app where a service offers it, particularly for email and banking. Your email account is the master key to most password resets.
- Save your backup codes somewhere safe and offline when enabling two-factor authentication, so losing a phone does not lock you out.
- Read push notifications before approving. Approving reflexively defeats the protection entirely.
If you have shared a code, act immediately: contact the bank or service, change the password, and report it. Speed limits the damage.
Frequently asked questions
Can my bank ever ask for my OTP? No. Neither can SASSA, SARS, your network or an employer. There is no legitimate exception.
I received a code I did not request. What does that mean? Someone is likely trying to log in with your password. Do not enter or share it. Change the password and enable two-factor authentication.
Is an authenticator app better than SMS? Yes. Authenticator codes are generated on your device and are not exposed to SIM-swap fraud or message interception.
What happens if I lose my phone with the authenticator on it? This is what backup codes are for — save them when you set it up. Most services also offer an account recovery route, though it is slower.
Someone claiming to be from my bank says they need the code to stop a fraudulent transaction. Is that real? No. That is the scam, and it is among the most common in South Africa. End the call and phone the bank on the number on your card.