SardineCon SF/2026

Learn More

¿Qué es OTP-bot scam?

Suscribite al newsletter

An OTP-bot scam uses an automated system that calls or texts victims to trick them into reading out one-time passcodes, so the fraudster can pass a login or payment check. It industrializes the last mile of account takeover, turning the theft of a single passcode into a scripted, repeatable phone call.

What is an OTP-bot scam?

An OTP bot is a piece of automation that harvests one-time passcodes by impersonating a trusted institution over the phone. The fraudster already has the victim's username and password, usually from a data breach or phishing kit. The only thing standing between them and the account is the one-time passcode sent by text or app. The bot exists to talk that code out of the victim.

Here is the mechanics. The attacker triggers a login or payment on the victim's real account, which causes the bank to send a genuine passcode to the victim's phone. At the same moment, the bot calls the victim with a convincing, automated script: this is your bank's fraud line, we detected suspicious activity, please confirm the code we just sent to verify your identity. The victim reads it back, the bot relays it to the operator, and the login or transfer completes.

For fraud teams, the OTP bot is what makes account takeover scale. It removes the need for a live social engineer on every call, so one operator can run many victims in parallel through a menu-driven panel.

How an OTP-bot scam unfolds

The bot orchestrates a race between the real passcode and the victim's trust:

  1. PreconditionAttacker has credentials Username and password are already stolen, so only the one-time passcode blocks access.
  2. TriggerForce a real code to send The operator starts a login or payment, making the bank text a genuine passcode to the victim.
  3. CallThe bot phones the victim An automated, spoofed call posing as the bank asks the victim to confirm the code to stop fraud.
  4. RelayCapture and complete The victim reads the code, the bot passes it to the operator, and the takeover or payment goes through.

Who is involved?

Who

Their role

The bot operator

Runs the OTP-bot panel, feeds in stolen credentials, and cashes out the accounts it opens.

The OTP-bot service

A rented tool that spoofs caller ID, plays the bank script, and captures the spoken code, often sold as a subscription.

The victim

The real account holder who receives a genuine passcode and a fake call at the same moment.

The bank or app

Sends the legitimate passcode and processes the login or payment the attacker is really driving.

What it looks like in practice

An account holder gets a text with a genuine login code from their bank. Seconds later their phone rings, the caller ID shows the bank's name, and an automated voice says the bank has blocked a suspicious login and needs the code just sent to confirm the account is safe. Rattled, the victim reads the six digits into the keypad.

Behind the scenes, the fraudster had just entered the victim's stolen username and password, which triggered that real code. With the digits relayed by the bot, the login completes from an unfamiliar device and location, and within minutes a payee is added and a transfer is initiated out of the account.

Why it matters for operators

OTP bots turn text-based one-time passcodes into a soft target. The control was meant to prove the person holds the phone, but if the person can be talked into reading the code aloud, the second factor adds little. Worse, because the passcode the victim receives is genuine, the message looks completely legitimate and the victim has no obvious reason to distrust it.

The practical lesson is that authentication signals cannot end at the passcode. A login that clears a valid one-time code but arrives from a new device, fresh IP, or unusual location, immediately followed by a payee change and a transfer, is the shape to catch. It also strengthens the case for phishing-resistant methods, such as app-based prompts bound to the device or passkeys, which cannot be read out over a phone.

What to watch in the data

  • Code plus new device. A successful one-time passcode entry from a device or location the account has never used before.
  • Fast payee then payment. A new beneficiary added within minutes of login, followed straight away by a transfer out.
  • Passcode-request bursts. Repeated one-time codes generated in quick succession as the operator retries or juggles multiple victims.
  • Inbound call correlation. Reports or telemetry showing a spoofed call arriving right after a genuine code was sent.
  • Credential-stuffing lead-in. Prior failed or successful logins consistent with reused breach credentials on the same account.

Quick questions

Does the victim receive a real or fake passcode?

A real one. The attacker triggers a genuine login or payment on the victim's account, so the bank sends a legitimate code. The fake part is the call that convinces the victim to read it back.

Why use a bot instead of a live caller?

Scale and consistency. A bot spoofs caller ID, plays a polished script, and captures the code automatically, so one operator can run many victims at once without staffing a call center.

Does this defeat multi-factor authentication?

It defeats one-time passcodes delivered by text or app when the code can be spoken aloud. Phishing-resistant methods that bind to the device, such as passkeys, are far harder to relay because there is no code for the victim to read out.

How is this different from a SIM swap?

A SIM swap steals the phone number so the attacker receives the code directly. An OTP bot leaves the number with the victim and instead tricks them into handing the code over.

What is the strongest server-side defense?

Treat the passcode as one signal among many. Combine it with device binding, location, and behavior, and add friction when a valid code arrives from a new device or is immediately followed by a payee change.

Where do the stolen credentials come from?

Usually earlier breaches, phishing pages, or credential stuffing. The OTP bot is the final step that turns a working username and password into full account access.

Qué saber junto con OTP-bot scam

Reporte

Informe de Fraude y ALD 2026

Olvídate de las predicciones. Este informe desglosa a qué se enfrentan realmente los equipos de fraude y ALD, y cómo responder.

Descargar reporte