Nobody shared the code, and the account was taken anyway
Event dated 20 May 2026 · Published 2 September 2026 · 3 sources
Every awareness programme contains the instruction. Nobody legitimate will ever ask for your one-time code. Do not read it out. Do not send it on. It is good advice, it is correct, and it describes a specific attack in which somebody asks for the code.
A relay does not ask. The victim reaches a page that looks like the sign-in page they expected, enters their password, and is prompted for the code exactly as they would be. Between those two moments the false page has used the password on the real site, which has issued a genuine prompt — so the code being requested is real, current, and about to be used by somebody else.
The advice is not wrong, it is narrow
This is the recurring difficulty with training as a control. Instructions have to be short to be remembered, and short instructions describe the version of the attack that existed when they were written. Attackers move to whatever the instruction does not cover, which in this case took no ingenuity at all: the message never mentions the code.
So the employee who follows the rule perfectly still loses the account, and the post-incident review finds somebody who did what they were taught. There is no lesson to reinforce, which is the uncomfortable part for anybody whose plan was more reinforcement.
What survives a relay
Only authentication that is bound to the site it is being used on. A hardware-backed key checks the address it is talking to before it responds, so a relay in the middle asks a question the key will not answer. Nothing is typed, therefore nothing can be forwarded.
Codes fail because they are portable by design: a short string that works wherever it is entered is a string that can be entered somewhere else. That is a property of the mechanism rather than a mistake by the person holding it.
Where training still earns its place
Reporting. The employee who realises afterwards that something was odd, and knows how to say so within minutes rather than deciding it was probably fine, shortens the interval between the compromise and somebody competent looking at it.
That is a narrower claim than the one awareness programmes are usually sold on, and it is defensible. Training is good at teaching people what to do after something has happened. It has never been reliable at preventing the thing, and a relay attack is the clearest demonstration available of why.