A caller tells you there is suspicious activity, a risky transfer, or an urgent account check. In the same minute, you receive a one-time code by SMS, a banking push, or a two-factor authentication prompt. That is exactly the friction point fraudsters exploit: they reuse a real security workflow to make you approve something that is not legitimate.
In 2026, the right reflex is not to judge whether the voice sounds convincing. You need to verify the workflow. A legitimate security call does not pressure you to read a code out loud, approve an unknown payment, or call back an improvised number. If you handle sensitive calls, the difference between a legitimate voice OTP flow and vishing now matters a lot.
Voice OTP, security callback, two-factor authentication: what are we talking about?
A legitimate flow may include an automated call, a one-time code, an in-app notification, or a verification callback. The key point is simple: the mechanism is meant to authenticate you to a known service, not to authenticate the caller. That is the gap vishing attacks exploit.
Guidance from Cybermalveillance.gouv.fr and Service-Public points to the same principle: a legitimate trusted organization should not ask for sensitive codes, passwords, or banking credentials over the phone.
The real test: what is the caller asking you to do right now?
Fraud scripts are better than they used to be. Attackers may know your name, bank, carrier, or recent history. But their goal is still repetitive. They want you to take immediate action that shifts risk onto you.
- More likely legitimate: you are invited to hang up and call back using an official number you find yourself on the website or app.
- More likely fraudulent: you are asked to read an OTP, quote an SMS, approve an operation "to block it", or call a number given verbally or by message.
- Highly suspicious: extreme urgency, threat of immediate loss, anti-fraud team language, and refusal to let you switch to a verified channel.
Why a real code can still support a real fraud
Many victims think: "If I received a real SMS from my bank, the call must be legitimate." That is false. In many cases documented by Cybermalveillance.gouv.fr's fake bank adviser guidance, the scammer triggers the sensitive action themselves. The code you receive is therefore genuine, but it is being used to authorize the fraudster's action.
In other words, the existence of an OTP proves nothing about the legitimacy of the call. It only proves that a sensitive action is happening somewhere.
Five checks that separate a legitimate security flow from vishing
1. Is the code for your own login, or to approve something you did not initiate?
If you did not request the login, reset, or transaction yourself, the code should not be used.
2. Can you switch to a channel you choose yourself?
A legitimate organization will accept that you hang up and call the official number. A fraudster usually tries to prevent that break.
3. Does the written message match the spoken story exactly?
Many OTP messages explicitly say never to share the code. If the caller asks you to do the opposite, you already have your answer.
4. Are you being told to "approve in order to block" something?
This is a common fake adviser pattern. A confirmation is presented as a way to cancel fraud. In reality, you may be authorizing it.
5. Does the caller tolerate delay and verification?
A legitimate service can handle scrutiny. A fraudster depends on urgency. If they become aggressive because you want to verify, that is already useful evidence.
For fraud, support, and customer teams: what needs to be framed
If your organization places security or verification calls, you need to reduce ambiguity with fraud scripts. That means never asking for an OTP orally, clearly giving official callback channels, and educating users on what a legitimate flow looks like.
This connects with topics already covered on HUHU: the checks against fake bank adviser scams, the correct reporting path after voice fraud, and more operational defenses through real-time alerts.
Quick checklist before acting during a call
- I did not initiate the action, so I do not use the code.
- I never read an OTP received during an incoming call.
- I hang up and call back using an official channel I selected myself.
- I verify the exact text in the SMS or push notification.
- If doubt remains, I treat the call as potentially fraudulent and document the incident.
FAQ
Is an automated voice call with a spoken code automatically legitimate?
No. An automated call can be part of a genuine flow, but you still need to verify who initiated the action and through which channel. Automation does not guarantee authenticity.
Can my bank ask me for an SMS code over the phone?
Official guidance says you should not disclose sensitive codes or banking details by phone. If that happens, stop the exchange and call back using an official number you found yourself.
What if I already shared a code?
You should act quickly: contact the relevant institution through an official channel, block the payment method if needed, and then use the right reporting route for your case.












