Why You're Being Asked for a Sign-In Code

EFA flagged this message because it's trying to get you to approve a sign-in or enter a verification code. That's one of the fastest-growing ways attackers take over accounts — and it works even if you never give away your password.

A real sign-in code is shown on your own screen. It isn't sent to you to type somewhere else.

If You're Seeing This, Here's What to Do:

1
Don't enter or approve any code unless you personally just started a sign-in yourself.
2
Check by opening the service directly in your browser or app — not through any link in the email.
3
If you didn't start it, delete the email. Someone may be trying to get into your account.

What Is a Sign-In Code?

Some sign-ins use a short code instead of a password. You've probably seen it setting up a streaming app on a TV or game console: the screen shows a code and tells you to go to a web page and enter it. That's a legitimate way to sign in a device that's hard to type on.

The important part: in the real version, the code appears on the device you're signing in on. You read it off your own screen. It is never emailed to you with instructions to go enter it somewhere.

How Attackers Abuse It

An attacker starts a sign-in to your account from their own computer. That generates a real code on the real Microsoft or Google page. Then they email that code to you — often from a hacked account that belongs to someone you trust — with a message like "a document was shared with you, approve access to view it."

If you enter the code, you're not signing yourself in. You're approving their device into your account. No password needed, and it can sail right past two-step verification, because you did the approving.

The Sender Looks Real

It often comes from a genuine, compromised account — so it passes the usual "is this a fake sender" checks.

The Link Is Real

It sends you to the genuine Microsoft or Google sign-in page. There's no fake website to spot.

The Trick Is You

The only thing out of place is that a code reached you by email at all. That's the red flag.

Urgency Does the Pushing

A shared file, an invoice, a request that can't wait — the pressure to act fast is what stops you noticing the code shouldn't be there.

Why EFA Showed You This

Because nothing about the sender or the link is fake, most security tools stay quiet on this attack. EFA looks at something different: the structure of the request itself. When a message is steering you to approve a sign-in code that you didn't ask for, we put a pause in front of it.

The warning isn't an accusation. If you genuinely just started a sign-in, you're fine — continue. If you didn't, you may have just avoided losing your account.

How to Stay Safer: Authenticator Apps

Many providers now offer stronger sign-in than emailed or typed codes — authenticator apps with number matching. Instead of typing a code, you tap an approval on your phone and match a number shown on the device that started the sign-in.

That small change breaks this attack at the root: an attacker on their own computer can't show you the matching number on your phone, so there's nothing for you to approve. Passkeys do the same thing even more strongly. If your provider offers either, turning it on is one of the best account-protection moves you can make.

Trust the pause.

A code that shows up in your inbox, asking to be entered somewhere, is worth a second look every time.

Protect What Matters — $1.99/month