One-time passcodes have a security problem, but it isn’t the passcode itself. Fraudsters are targeting phone numbers that receive OTPs to take over customer accounts. Through tactics such as SIM swaps, unauthorized number reassignments and call forwarding, criminals can redirect calls or messages to devices they control. The OTP may work exactly as intended and still give a fraudster the final credential needed to complete an account takeover.
That risk is growing. The global rate of suspected digital account takeover fraud increased 37% from 2024 to 2025. For fraud, identity and authentication leaders, the implication is clear: An OTP only protects an account when it reaches the intended person.
Yet OTPs remain one of the most familiar forms of step-up authentication. They’re fast, widely accessible and easy for consumers to understand. They also play a critical role when someone needs to recover an account, reset a password or approve a higher-risk transaction.
Organizations don’t need to abandon OTPs. They need greater confidence the phone receiving the code is still controlled by the person they intend to authenticate.
Why one-time passcodes still matter for customer authentication
Organizations have more authentication choices than ever, but no single method addresses every consumer, channel and use case. For instance:
- Biometrics can strengthen layered authentication, but they don’t eliminate risks associated with compromised devices, account recovery abuse, or biometric spoofing attacks.1
- Passkeys represent an important direction for authentication, but usage hasn’t caught up with availability. Overall, 93% of accounts were eligible for passkeys, while 36% had a passkey enrolled and only 26% of sign-ins used them.2
OTPs continue to fill the gaps. Nearly a third of US business leaders identified OTPs as their preferred secondary authentication method.3 More than a quarter of US consumers said OTPs were their preferred method of online account authentication, second only to multifactor authentication.4
Their value extends well beyond routine login. An OTP provides an accessible second factor when an organization needs additional confidence in an identity. It also supports important account recovery processes, including password resets, locked account recoveries and requests to change contact information.
For a consumer who can’t access an account, these processes aren’t routine. The person may need to make a payment, review private information or respond to an urgent notification. An unfamiliar or difficult to complete authentication step can increase frustration, generate customer service calls or prevent a legitimate customer from regaining access to their account.
OTPs help organizations introduce protection through a process consumers already know. They can support layered authentication without forcing every person to take the same journey or requiring immediate adoption of a new technology.
That combination of familiarity and reach makes OTPs valuable. It also makes the phone number behind them an attractive target.
Possession of an OTP shows someone received the code. It doesn’t always prove the code reached the legitimate customer. As fraudsters focus their attention on passcode interception using phone takeover, organizations need to reconsider what successful OTP entry actually proves.
Phone takeover changes what one-time passcode authentication proves
Traditional OTP authentication often treats control of a phone number as evidence of identity. That assumption no longer provides enough confidence on its own.
A fraudster may use exposed personal information to convince a mobile carrier to transfer a consumer’s number to a SIM card the fraudster controls. A phone number may also be reassigned without a consumer’s knowledge or calls may be forwarded to another device. An authentication system may have no visibility into those changes.
From the organization’s perspective, the process worked. A code was generated, sent to the phone number on file and entered correctly. From the consumer’s perspective, the company they trusted to protect their security just provided a criminal control of their account.
This threat becomes more significant as compromised identity information grows easier to obtain. US data breach volume increased 47% from 2024 to 2025, exposing the necessary identity credentials necessary to support phone takeover, account takeover and new account fraud. In fact, exposed phone numbers are already widely used in consumer scams. Consumers who said they were targeted with fraud reported smishing and vishing among the top three fraud schemes they experienced.
The effects go beyond direct fraud losses. Consumers view security as part of their experience with an organization. Seventy-six percent said confidence their personal data is protected is very important when deciding where to do business.5
When authentication fails to protect an account, the organization risks its reputation and losing the customer’s trust.
How real-time phone risk signals protect OTP delivery
A more secure OTP process changes the order of operations. Instead of sending a code and assuming control of the number proves legitimacy, organizations can evaluate phone risk before OTP delivery.
Real-time telephony network signals can help determine whether a phone number appears connected to the person claiming it and if recent activity indicates possible compromise. Those assessments can take place behind the scenes — without requiring another action from the consumer.
A successfully entered OTP proves code possession. It no longer reliably proves trusted identity.
When signals indicate low risk, the organization can send the OTP and allow the customer to continue. When signals show possible compromise, the fraud team can withhold the code, stop the transaction or direct the customer to another verification method.
This risk-informed approach can help protect OTP delivery without increasing visible friction for most trusted consumers. It also gives organizations the opportunity to intervene before a compromised phone number becomes the final step in an account takeover.
The strategic shift is straightforward: Don’t ask only whether someone can provide the OTP. Determine whether the phone receiving it can still be trusted.
How to begin re-thinking secure one-time passcode authentication
OTPs will continue to play an important role in step-up authentication and account recovery. Their familiarity helps consumers navigate important moments, while their flexibility allows organizations to add protection when risk is elevated.
The challenge is that many organizations still evaluate OTP success using the wrong measure.
If a code is sent, received and entered correctly, authentication is often considered successful. But successful OTP entry only proves someone received the code. It doesn't necessarily prove the intended customer received it.
As phone takeover techniques become more common, fraud teams need greater confidence in the phone number behind the authentication event. The question is no longer "Was the OTP entered correctly?" It's "Can the phone receiving the OTP still be trusted?" Organizations that make this shift can identify risk earlier, intervene before account takeover occurs and preserve the convenience consumers expect from OTP authentication.
The practical next question becomes how to identify trusted versus potentially compromised phone numbers in real time and how to apply those insights consistently across digital, IVR and contact center channels.
The ebook, Why One-Time Passcodes Fail: Restoring Trust in OTP Authentication, provides a framework for assessing OTP vulnerabilities, understanding phone takeover risk and strengthening authentications decisions before a code is sent. Learn how to move beyond OTP delivery and build greater confidence in the identity behind every authentication event.
End notes
1 CFS Tools, IA-5(17): Presentation Attack Detection for Biometric Authenticators
2 FIDO Alliance, Passkey Index 2025
3 TransUnion, H2 2025 Update: Top Fraud Trends
4 TransUnion, H1 2026 Update: Top Fraud Trends
5 TransUnion, Q2 2026 Consumer Pulse Study