Tech

Hackers are using this nasty text-message trick to break into people's accounts

Read in app
woman venetian mask venice disguise lipstick wig hair
The person who sent that text message might not be who you think.  Marco Di Lauro/Getty Images

Two-factor authentication is a godsend for securing your accounts.

It requires a second level of proof of who you are — typically a code sent to your phone — before you can log in. This prevents anyone from gaining unauthorised access to your account, even if they manage to get hold of your password.

However, hackers and hijackers are managing to find ways around it.

Earlier this week, Alex MacCaw, cofounder of data API company Clearbit, shared a screenshot of a text attempting to trick its way past two-factor authentication (2FA) on a Google account.

Here's how it works: 

  • The attacker sends the target a text message, pretending to be the very company that the target has an account with.
  • They say they have detected "suspicious" activity to the account, and so are sending the 2FA code to the target, which they should then text back to them to avoid having their account locked.
  • The victim, worried they are being hacked and not wanting to lose access to their data, sends the code back, believing they have thwarted the attempted hack.
  • But in doing so, they actually give the hacker the one thing they needed to break into the account.
  • The hacker enters the victim's password, followed by this ill-gotten 2FA code, and they're in.

The attacker can sometimes even spoof their identity — so the text looks like it comes from Google, or Facebook, or Apple, rather than an unknown number.

Of course, the attacker still needs the victim's password for this to work. But there are a number of ways they could get hold of it. Often they look at data dumps from old hacks for emails/usernames and passwords that they then try on other sites, because so many people reuse passwords across multiple accounts and platforms.

Huge databases of tens of millions of email addresses and passwords have been floating around in the last few weeks — notably from LinkedIn and MySpace. So if you reuse passwords, your login details may be being shared online right now without you realising.

The text message that Alex MacCaw shared on Twitter is above. To stay safe, use a strong, unique password for every account you have — managing them all with a password manager if necessary — and don't text your two-factor authentication codes to anyone, even if they appear legitimate.

Read next

Rob Price was a senior correspondent at Business Insider, based in San Francisco. He wrote investigations and long-form features about platforms, people, and power in Silicon Valley.His stories variously led to attorney general investigations, large-scale internal reviews at major tech companies, high-profile personnel departures, citation by state and federal lawmakers, and the closure of a well-funded startup. His 2022 story on the Bitfinex hack is being adapted into a feature film, and in 2024 he received an SPJ NorCal Excellence in Journalism award for his reporting on AI and relationships.Rob's scoops and exclusive stories were cited by The New York Times, Bloomberg, the BBC, Associated Press, Reuters, CNBC, Politico, The Guardian, Axios, and many other national and international publications. His writing has also been published in or syndicated by The Washington Post, The Independent, Vice, Slate, and elsewhere, and he appeared on CNN, the BBC, CBS, Reuters, ABC Australia, and other broadcast media to discuss technology, business, and culture.He worked for Business Insider from 2015 to 2025. Prior to joining the features team, Rob covered Facebook and Silicon Valley, and before that wrote about tech business, policy, and the gig economy in London. Between September and October 2019, he was acting executive editor for Business Insider's UK bureau. He also sat on the board of directors for the San Francisco Press Club, the leading non-profit media advocacy group in the Bay Area, and was a volunteer crew member at the Marine Mammal Center, the world's largest animal hospital for marine mammals. You can contact Rob Price via email at robaeprice@gmail.com, or +1 650-636-6268 (Signal / WhatsApp / Cell). Selected stories:— They spoke out against their employer. Then they were hit with trade secrets suits.— The rise of 'shadow stand-ins'— App, Lover, Muse: Inside a 47-year-old Minnesota man's three-year relationship with an AI chatbot— Deel Speed: The inside story of a $12 billion HR startup's breakneck growth— Private islands, flying cars, and psychedelic parties: Inside the wild post-Google lives of Larry Page and Sergey Brin— 'I want your Instagram account': First came the threatening texts, followed by the SWAT teams. Then someone wound up dead.— Inside Iconiq: How Mark Zuckerberg's banker built a secret Silicon Valley empire and made billions— Gaia was a wildly popular yoga brand. Now it's a publicly traded Netflix rival pushing conspiracy theories while employees fear the CEO is invading their dreams— A drunken late-night assault allegation has roiled the secretive world of Mark Zuckerberg's private family office. Personal aides are speaking out about claims that household staff endured sexual harassment and racism from their colleagues.