Why You're Being Asked for a Sign-In Code
EFA flagged this message because it's trying to get you to approve a sign-in or enter a verification code. That's one of the fastest-growing ways attackers take over accounts — and it works even if you never give away your password.
A real sign-in code is shown on your own screen. It isn't sent to you to type somewhere else.
If You're Seeing This, Here's What to Do:
What Is a Sign-In Code?
Some sign-ins use a short code instead of a password. You've probably seen it setting up a streaming app on a TV or game console: the screen shows a code and tells you to go to a web page and enter it. That's a legitimate way to sign in a device that's hard to type on.
The important part: in the real version, the code appears on the device you're signing in on. You read it off your own screen. It is never emailed to you with instructions to go enter it somewhere.
How Attackers Abuse It
An attacker starts a sign-in to your account from their own computer. That generates a real code on the real Microsoft or Google page. Then they email that code to you — often from a hacked account that belongs to someone you trust — with a message like "a document was shared with you, approve access to view it."
If you enter the code, you're not signing yourself in. You're approving their device into your account. No password needed, and it can sail right past two-step verification, because you did the approving.
The Sender Looks Real
It often comes from a genuine, compromised account — so it passes the usual "is this a fake sender" checks.
The Link Is Real
It sends you to the genuine Microsoft or Google sign-in page. There's no fake website to spot.
The Trick Is You
The only thing out of place is that a code reached you by email at all. That's the red flag.
Urgency Does the Pushing
A shared file, an invoice, a request that can't wait — the pressure to act fast is what stops you noticing the code shouldn't be there.
Why EFA Showed You This
Because nothing about the sender or the link is fake, most security tools stay quiet on this attack. EFA looks at something different: the structure of the request itself. When a message is steering you to approve a sign-in code that you didn't ask for, we put a pause in front of it.
The warning isn't an accusation. If you genuinely just started a sign-in, you're fine — continue. If you didn't, you may have just avoided losing your account.
How to Stay Safer: Authenticator Apps
Many providers now offer stronger sign-in than emailed or typed codes — authenticator apps with number matching. Instead of typing a code, you tap an approval on your phone and match a number shown on the device that started the sign-in.
That small change breaks this attack at the root: an attacker on their own computer can't show you the matching number on your phone, so there's nothing for you to approve. Passkeys do the same thing even more strongly. If your provider offers either, turning it on is one of the best account-protection moves you can make.
Trust the pause.
A code that shows up in your inbox, asking to be entered somewhere, is worth a second look every time.
Protect What Matters — $1.99/month