I shared a bank or itsme code: what should I do now?

A one-time code or itsme approval can authorise a login, device or transaction. Do not try to fix this with the caller. Return directly to your bank or the official service.

Information checked : 2026-09-10

Priority / Safe channel / Action

  1. Priority - Limit the risk now

    If you shared a bank code, OTP, card-reader code or itsme approval, contact the official service immediately and have access and transactions checked.

  2. Safe channel - Do not follow the channel you received

    5 useful official sources listed below.

  3. Action - Contact the right service

    I already clicked

Transparency and Sources

Page checked
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

Immediate summary

  • A one-time code or itsme approval can authorise a login, device or transaction. Do not try to fix this with the caller. Return directly to your bank or the official service.

What this action may have triggered

  • The code may have approved a different action from the one described by the caller.
  • A device, beneficiary or session may have been added even when no debit is visible.

Do this now

  • End the call and contact your bank immediately through the number on your card or its official website.
  • State what type of code you shared and when, and ask for access, devices, beneficiaries and pending transactions to be checked.
  • If it involved itsme, open the app yourself and follow its official account-security procedure.

Emergency timeline

  • Now, 0-5 min: stop the interaction, close the suspicious page and do not use any link, number or QR code from the message.
  • Within 30 min: contact the bank, Card Stop or the relevant service through an official channel if money, a card, a code or an account is involved.
  • Today: write a short timeline with what you saw, what you did, which amounts or accounts are involved and which measures were already taken.
  • This week: monitor accounts, sessions, passwords and follow-up messages; stay alert for fake helpdesk or bank calls.

Do not do this

  • Do not share a second code to supposedly cancel the first.
  • Do not approve another notification requested by the caller.
  • Do not call back through a number supplied in the message or call.

What should be checked

  • Ask whether a login, device, beneficiary or payment was approved.
  • Check pending activity as well as completed debits.

Useful evidence to keep

  • Keep the message, displayed number, time, type of code and observed transactions.
  • Never publish the code or complete banking details.

Prepare the next steps without false promises

  • Record the bank's actions and any case reference.
  • If harm is confirmed, prepare a chronological report of what happened.

First identify which code was shared

  • A banking code, card-reader code, SMS code and itsme approval do not carry the same risk. Tell the bank or service exactly what you shared and what the fraudster claimed it would do.
  • Do not start with a vague statement such as "I was hacked". More useful details are the time, type of code, app or device used, name used by the caller and visible transaction.

Have active access checked

  • Do not only ask whether money has already left. Ask for new devices, sessions, beneficiaries, limits, card settings and scheduled transactions to be checked.
  • For itsme, the key question is whether you initiated the action yourself. An unexpected approval should be reviewed through the official itsme procedure and the affected account.

Prevent a second approval

  • Fraudsters often ask for a second code to supposedly cancel the first. That may authorise another action instead.
  • Do not stay in the conversation. Call your bank's official number yourself or open the official app already installed on your device.

Limits of this guidance

  • This page helps handle a shared code or unexpected itsme approval. It cannot see which action was actually approved and does not replace checks by the bank or relevant service.
  • Use only the number on your card, the banking app already installed on your device or the official website you type yourself. Record who you spoke to, which code type was shared and which access was blocked.

What to do now

  • If you have not acted, do not click further and open the named service's official channel yourself.
  • If you clicked, close the page, enter nothing else and note what information was shown or requested.
  • If you shared a code, card, password or payment, contact your bank or the relevant official service immediately.
  • Keep the message, time, link used and any useful screenshots. Share them only with an official reporting channel or a trusted helper.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For this i shared a bank or itsme code situation, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for this i shared a bank or itsme code situation depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

Frequently asked questions

The code has expired. Am I safe?

It should no longer be reusable, but the action approved when it was shared may already have happened. Have access and transactions checked.

Should I change every password?

Change the affected access first from a trusted device. The bank or official service can tell you what else needs to be reset.

Can a genuine adviser ask for a code?

A code or approval authorises an action. Never share it with an unexpected caller.

Useful official sources

Check a similar message

I already clicked

Prepare my next steps