What Verification Codes, PINs & Identity Checks covers

This section covers codes and PINs used to confirm identity, and the terms that circulate around them.

A PIN and a one-time code are different things and are worth separating clearly. A PIN is a standing secret you choose and reuse — your card PIN, your phone passcode. A one-time code is generated for a single action and expires within minutes. Both prove something about you, and neither should ever be shared, but they fail differently: a leaked PIN keeps working until you change it, while a leaked one-time code is useful only immediately.

This section also covers terms that appear in South African search results around PINs and identity where the subject is folklore rather than technology. Where a search reflects a claim about influencing or obtaining someone’s PIN by non-technical means, the honest answer is that no such method works — and that the practical risk is entirely conventional: shoulder-surfing, card skimming, and being persuaded to disclose the number.

That framing matters because it points at the defences that genuinely help. Covering the keypad, checking a card machine before inserting a card, and refusing to say a PIN aloud protect you. Nothing else needs to.

Browse individual used-for guides

Most searched questions in this topic

How the guides in this section differ

Standing secret or single-use. A PIN persists until changed. A one-time code expires. Both are private; the response to a compromise differs.

Device, card or account. A phone passcode protects a handset. A card PIN authorises payments. An account PIN or password protects a service. Compromise of one does not automatically expose the others unless you have reused it.

Technology or folklore. Some searches in this area concern claimed non-technical methods of obtaining PINs. The guides address these plainly: the mechanisms people actually lose money to are observation, skimming and persuasion.

SecretProtectsIf compromised
Card PINCard payments and withdrawalsContact the bank, block the card
Phone passcodePhysical access to the handsetChange it; check account access
Account passwordAn online serviceChange it, and anywhere reused
One-time codeA single transactionExpires quickly; check the account

Related topics and alternatives

Safety, accuracy and next-step checks

These guides follow official banking and cyber-safety guidance. They will never ask you to disclose a PIN or code.

Points worth carrying:

A final habit worth building, because it defeats nearly every technique in this section at once: never act on an incoming contact. If a message or call prompts you to enter a PIN, confirm a code, or move money, stop and reach the organisation yourself using a number you already had — from your card, your statement or their official site. Criminals rely on the momentum of a conversation they started. Ending it and calling back costs a minute and removes the entire basis of the fraud.

Frequently asked questions

What is the difference between a PIN and an OTP? A PIN is a standing secret you reuse. A one-time PIN is generated for a single action and expires within minutes. Neither should be shared.

Can bank staff ask for my PIN? No. There is no legitimate circumstance in which any organisation needs your PIN. A request for it is fraud.

Someone at the ATM offered to help me. Is that safe? No. Card swapping and PIN observation at ATMs are common. Decline help, cover the keypad, and if a card is retained, phone the bank yourself before leaving.

Is there a way to obtain someone’s PIN without them knowing? There is no method that works other than observation, skimming devices and persuasion. Protecting against those three protects you.

What should I do if I think someone knows my PIN? Change it immediately and contact your bank. If the card may have been skimmed, ask for it to be blocked and replaced.