Real Two-Factor Prompt vs OTP Bot and Push Bombing
How to recognise a genuine authentication request from a fraudulent OTP-harvesting bot or push-notification bombing attack attempting to break into your account.
Last reviewed: 1 June 2026
A two-factor prompt you triggered yourself is one of the safest things on your phone, and most of the ones you see are exactly that: you logged in, the code arrived, you used it. The attack versions invert the order. A code or an approval request turns up when you did nothing, which usually means somebody already has your password and is standing at the door. Then the pressure begins, either a caller claiming to be from the platform security team asking you to read the code back so they can block an intruder, or a stream of approval prompts arriving through the night until tapping one feels like the only way to get any sleep. The distinction that matters most is simple. If you did not start it, nothing you approve will help you.
Side-by-side comparison
| Real two-factor prompt | OTP bot / push bombing | |
|---|---|---|
| What triggered the request | You just logged in or initiated a transaction yourself | You received a code or push with no action on your part |
| Who is asking for the code | The website or app you are using — no phone call or message asks you to read it aloud | An automated voice call or SMS asks you to press a digit or read back a code |
| Volume of push notifications | One approval request per login attempt | Repeated push requests in quick succession — sometimes dozens — hoping you approve one |
| Urgency language | Neutral confirmation message; no threat if you ignore it | 'Your account will be locked unless you approve now'; caller claims to be from the platform |
| Caller ID | Legitimate services do not call you to approve a push or read a code | Spoofed caller ID showing the real company name to build false trust |
| What happens if you deny | Your session is blocked; you can try again legitimately | Calls or pushes resume; caller may become more aggressive |
Common red flags
- You receive an OTP or push notification without having attempted to log in
- An automated voice call asks you to press a key or read back a verification code
- Multiple push-approval requests arrive within seconds
- Caller claims to be from the platform's security team and asks you to approve the notification to 'stop the attacker'
- Message contains urgency language about account suspension
Verification steps
- Deny all unexpected push requests and do not share OTP codes with anyone calling you
- Log in directly to the service's website (type the URL manually) to check for real account alerts
- Change your password and review recent login activity if you receive unexpected codes
- Switch from SMS OTP to an authenticator app where possible, as app-based codes cannot be intercepted by voice bots
What not to do
- Do not approve a push notification you did not trigger yourself
- Do not read an OTP aloud to any caller, even if caller ID shows your bank or service provider
- Do not approve 'just one' push request to stop the notifications — that is exactly what the attacker wants
A safe response
Deny every prompt you did not start, and never read a code aloud to anyone who rang you, whatever the caller display says. If a caller pushes, say you will contact the company yourself, then hang up. Now treat the password as compromised: open the service by typing the address yourself, change the password to one you use nowhere else, sign out all active sessions, and check the recovery email and phone number for entries you did not add. Move from text message codes to an authenticator app or a security key if the service offers it. If you did approve a prompt, do all of this now and tell the platform.
Frequently asked questions
I got a code I did not request but I ignored it. Do I need to do anything?
Yes, something small but worth doing today. A code arriving unrequested usually means someone entered your username and password correctly, so the password is the part that has already failed. Change it to something you use nowhere else, sign out all sessions, and check the recovery email address and phone number on the account. If that password is reused on other services, change it there too, and switch to an authenticator app where you can.
Is SMS two-factor still worth using?
SMS OTP is much better than no second factor, but it is vulnerable to SIM-swapping and OTP bots. Where possible, prefer an authenticator app or a hardware security key.
Why would a push-bombing attacker claim to be from my bank's security team?
The social-engineering script is designed to make you think approving the push will stop an attack already in progress. In reality you are handing the attacker the access they need.