Free lesson · Skill · 6 min

OTPs, PINs, passwords, and push approvals

Lesson 7 of 10 in AI Fraud Awareness Foundations

The one idea

Your OTPs, PINs, passwords, and push approvals are not information ABOUT your account — they ARE your account. Everything a fraudster does upstream (the fake page, the cloned voice, the urgent story) exists to reach this moment: you reading out six digits or tapping Approve.

Compare:

"The bank agent needed the OTP to cancel the fraudulent debit order." — the OTP was the authorisation for the transfer that emptied the account.

versus

"The message says this OTP adds a new beneficiary. I did not add a beneficiary. I am not reading this to anyone — I am calling the fraud line."

The two rules

Rule one: the bank never needs your OTP, PIN, or password to help you. It generated the OTP; it does not need it read back. Anyone asking for a code is using it to approve something as you, right now, while you are on the phone.

Rule two: read the words. An OTP or push notification names exactly what it approves — "add beneficiary", "payment of R14,900 to X", "change daily limit". The text is your last line of defence: approve only what you initiated yourself, and treat an approval you did not initiate as an attack in progress — reject it and call the bank, because someone already has your password.

Try it now

Find the last OTP or push approval in your messages. Read the full text and write down: what exact action did it authorise? If one arrived right now that you did not initiate, write the two things you would do (reject; call the official fraud line).

Your win today

Codes and approvals are the keys, not the paperwork. You read every approval message and never share a code with anyone, including "the bank".

Turn the idea into a reflex

Members practice this against a real AI assistant, get feedback on the prompt, then review it before the idea fades.

Practice this lesson free