Getting Verification Codes You Didn't Request? How to Tell Spam From Account Compromise
Home>Incident Reports>Getting Verification Codes You Didn't Request? How to Tell Spam From Account Compromise Time to triage
under an hour
Incident
The triage playbook
What we told the user
Why this isn't a compromise signal
What would change the answer
Outcome
Key takeaways
Takeaway
unexpected OTPs are scary by default, but the email's own language tells you whether it's registration (low risk) or login (high risk).
Takeaway
"same sender, repeating" usually means one person is mistyping or a bot is hammering a signup form — not account compromise.
Takeaway
never enter an unrequested code anywhere; never click a link inside one of these emails.
Takeaway
real compromise attempts come with other signals: password reset requests, login alerts, 2FA prompts for services you didn't just access.
Takeaway
the best confirmation is a password reset from the service's actual website, not from the email.