h.
HUHU.fr
PROTECTION
August 11, 20265 min read

Voice OTP, security callback, two-factor authentication: how to tell a legitimate call from vishing

LucieHUHU.fr Editor

A real OTP does not prove a call is legitimate. Here is how to separate a normal security flow from vishing before you approve anything.

Voice OTP, security callback, two-factor authentication: how to tell a legitimate call from vishing

A caller tells you there is suspicious activity, a risky transfer, or an urgent account check. In the same minute, you receive a one-time code by SMS, a banking push, or a two-factor authentication prompt. That is exactly the friction point fraudsters exploit: they reuse a real security workflow to make you approve something that is not legitimate.

In 2026, the right reflex is not to judge whether the voice sounds convincing. You need to verify the workflow. A legitimate security call does not pressure you to read a code out loud, approve an unknown payment, or call back an improvised number. If you handle sensitive calls, the difference between a legitimate voice OTP flow and vishing now matters a lot.

Voice OTP, security callback, two-factor authentication: what are we talking about?

A legitimate flow may include an automated call, a one-time code, an in-app notification, or a verification callback. The key point is simple: the mechanism is meant to authenticate you to a known service, not to authenticate the caller. That is the gap vishing attacks exploit.

Guidance from Cybermalveillance.gouv.fr and Service-Public points to the same principle: a legitimate trusted organization should not ask for sensitive codes, passwords, or banking credentials over the phone.

The real test: what is the caller asking you to do right now?

Fraud scripts are better than they used to be. Attackers may know your name, bank, carrier, or recent history. But their goal is still repetitive. They want you to take immediate action that shifts risk onto you.

  • More likely legitimate: you are invited to hang up and call back using an official number you find yourself on the website or app.
  • More likely fraudulent: you are asked to read an OTP, quote an SMS, approve an operation "to block it", or call a number given verbally or by message.
  • Highly suspicious: extreme urgency, threat of immediate loss, anti-fraud team language, and refusal to let you switch to a verified channel.

Why a real code can still support a real fraud

Many victims think: "If I received a real SMS from my bank, the call must be legitimate." That is false. In many cases documented by Cybermalveillance.gouv.fr's fake bank adviser guidance, the scammer triggers the sensitive action themselves. The code you receive is therefore genuine, but it is being used to authorize the fraudster's action.

In other words, the existence of an OTP proves nothing about the legitimacy of the call. It only proves that a sensitive action is happening somewhere.

Five checks that separate a legitimate security flow from vishing

1. Is the code for your own login, or to approve something you did not initiate?

If you did not request the login, reset, or transaction yourself, the code should not be used.

2. Can you switch to a channel you choose yourself?

A legitimate organization will accept that you hang up and call the official number. A fraudster usually tries to prevent that break.

3. Does the written message match the spoken story exactly?

Many OTP messages explicitly say never to share the code. If the caller asks you to do the opposite, you already have your answer.

4. Are you being told to "approve in order to block" something?

This is a common fake adviser pattern. A confirmation is presented as a way to cancel fraud. In reality, you may be authorizing it.

5. Does the caller tolerate delay and verification?

A legitimate service can handle scrutiny. A fraudster depends on urgency. If they become aggressive because you want to verify, that is already useful evidence.

For fraud, support, and customer teams: what needs to be framed

If your organization places security or verification calls, you need to reduce ambiguity with fraud scripts. That means never asking for an OTP orally, clearly giving official callback channels, and educating users on what a legitimate flow looks like.

This connects with topics already covered on HUHU: the checks against fake bank adviser scams, the correct reporting path after voice fraud, and more operational defenses through real-time alerts.

Quick checklist before acting during a call

  • I did not initiate the action, so I do not use the code.
  • I never read an OTP received during an incoming call.
  • I hang up and call back using an official channel I selected myself.
  • I verify the exact text in the SMS or push notification.
  • If doubt remains, I treat the call as potentially fraudulent and document the incident.

FAQ

Is an automated voice call with a spoken code automatically legitimate?

No. An automated call can be part of a genuine flow, but you still need to verify who initiated the action and through which channel. Automation does not guarantee authenticity.

Can my bank ask me for an SMS code over the phone?

Official guidance says you should not disclose sensitive codes or banking details by phone. If that happens, stop the exchange and call back using an official number you found yourself.

What if I already shared a code?

You should act quickly: contact the relevant institution through an official channel, block the payment method if needed, and then use the right reporting route for your case.

About the Author

Lucie

HUHU.fr Editor

Everything you need to know about telephony for your sales teams. We strive to provide as many articles as possible to support your commercial growth.

Articles in Protection

Fake bank advisor: 8 checks before you call back or approve a transaction
Protection

Fake bank advisor: 8 checks before you call back or approve a transaction

With a fake bank advisor, the right move is not speed but control. Here are 8 practical checks before any callback, SMS code, or transaction approval.

Jul 9, 20267 min
33700 and voice spam: how to report a fraudulent call through the right channel
Protection

33700 and voice spam: how to report a fraudulent call through the right channel

33700 is useful for reporting some suspicious calls and text messages, but not every case. Here is when to use it, when Bloctel is more appropriate, and when to escalate to your carrier, PHAROS, or a police report.

Jul 5, 20265 min
Voice cloning: 8 checks to verify a call is really human
Protection

Voice cloning: 8 checks to verify a call is really human

With voice cloning, a familiar voice is no longer enough. Here are 8 practical checks to verify a call, break urgency, and avoid fraud.

Jun 5, 20267 min
J'alerte l'Arcep, 33700, Bloctel: which reporting channel fits which kind of spam?
Protection

J'alerte l'Arcep, 33700, Bloctel: which reporting channel fits which kind of spam?

Bloctel, 33700, and J'alerte l'Arcep do not serve the same purpose. Here is which channel to use for telemarketing, smishing, or a broader operator issue.

Jun 1, 20266 min
Premium-rate 08 numbers: how to identify them before calling
Protection

Premium-rate 08 numbers: how to identify them before calling

Not every number starting with 08 is premium-rate. Here is how to tell a free 0800 number from a paid 089 number, spot scam signals, and verify a number before calling back.

Apr 20, 20265 min
Block Unwanted Calls: 7 Proven Methods to Stop Phone Spam
Protection

Block Unwanted Calls: 7 Proven Methods to Stop Phone Spam

Tired of constant spam calls? Learn 7 proven methods to block unwanted calls on any phone, from built-in settings to powerful apps. Take back control of your phone today.

Mar 5, 20263 min

Protect your numbers now

Monitor your number reputation and anticipate blocks before they impact your conversions

Voice OTP and vishing: spotting a legitimate call in 2026 | HUHU.fr