Skip to content
The Cyber Security Place

Nobody shared the code, and the account was taken anyway

Event dated 20 May 2026 · Published 2 September 2026 · 3 sources

Campaigns reported through May 2026 chained phishing into credential theft,one-time code interception, installation of remote access tools and account takeover. The interception step is worth understanding precisely, because the standard advice misdescribes it. The code is not guessed and it is not asked for by a stranger on the telephone: the person types it into a page that relays it to the real site within seconds. Told never to share their code, they did not believe they were sharing it with anybody. They were signing in, and something in the middle was signing in too.

Every awareness programme contains the instruction. Nobody legitimate will ever ask for your one-time code. Do not read it out. Do not send it on. It is good advice, it is correct, and it describes a specific attack in which somebody asks for the code.

A relay does not ask. The victim reaches a page that looks like the sign-in page they expected, enters their password, and is prompted for the code exactly as they would be. Between those two moments the false page has used the password on the real site, which has issued a genuine prompt — so the code being requested is real, current, and about to be used by somebody else.

The advice is not wrong, it is narrow

This is the recurring difficulty with training as a control. Instructions have to be short to be remembered, and short instructions describe the version of the attack that existed when they were written. Attackers move to whatever the instruction does not cover, which in this case took no ingenuity at all: the message never mentions the code.

So the employee who follows the rule perfectly still loses the account, and the post-incident review finds somebody who did what they were taught. There is no lesson to reinforce, which is the uncomfortable part for anybody whose plan was more reinforcement.

What survives a relay

Only authentication that is bound to the site it is being used on. A hardware-backed key checks the address it is talking to before it responds, so a relay in the middle asks a question the key will not answer. Nothing is typed, therefore nothing can be forwarded.

Codes fail because they are portable by design: a short string that works wherever it is entered is a string that can be entered somewhere else. That is a property of the mechanism rather than a mistake by the person holding it.

Where training still earns its place

Reporting. The employee who realises afterwards that something was odd, and knows how to say so within minutes rather than deciding it was probably fine, shortens the interval between the compromise and somebody competent looking at it.

That is a narrower claim than the one awareness programmes are usually sold on, and it is defensible. Training is good at teaching people what to do after something has happened. It has never been reliable at preventing the thing, and a relay attack is the clearest demonstration available of why.