Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I had a legitimate call from my credit union last month. They were following up on a problem I had reported with their on-line bill pay system. Toward the beginning of the call, they wanted to verify that it was me and they asked me to provide them with the 2FA code they had just texted to me. I declined and told them that this is what scammers do. They agreed with me and encouraged me to call them back at the number on my ATM card.

I thought it was really unprofessional of them to operate this way.



It's insane for them to request that you read a 2fa code to a human over the phone. Even if you called them. Escalate and get their policies changed, or get them fired if they're violating policy.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: