2FA notification without your login

Do not approve a request that has not been started from your website. Check account activity by a known application or address.

2 min readFor execution: 5-15 minutes for first check
In this guide

The phone asks if you are allowed to log in, even though you are reading the messages. Do not press “Yes” for peace or after the call of a caller claiming support. Approval is intended for a specific operation started by you.

Refuse an unknown request

If the application allows, select a refusal or a statement that it is not you. Do not prescribe the number read by the caller and do not share the code from the application. Multiple requests may be intended to encourage you to accidentally approve.

First check that the login has not been started on your other device. If you can't connect the request to your action, still don't approve it. The location in the message itself is not enough to confirm the identity.

Open independent path settings

Run a known application or use the saved tab. View the latest security events, active sessions and recovery methods. Do not follow the link in an additional “helpful” text.

An unexpected request is not in itself proof that the password has been leaked: some services allow you to log in without a password. If you see an attempt using a password that has not been deliberately revealed, change it to unique. Please report repeated attempts to the administrator at your business account.

If request has been approved

From a trusted device, go to account security. Complete unknown sessions, check the added login and recovery methods, and access applications. Password change does not always end all sessions – also use the function of cancelling them.

If you have lost access, use an official recovery at the supplier. Do not buy “recovery” from the person who spoke after publication of the problem information.

You can order actions in post-phishing response plan: Select the option to enter a password, code or login approval. The plan does not connect to the account and does not perform these actions for you.

Restrict further attempts

Check if the service supports passkeys or a hardware key. Phishing-resistant methods reduce the risk of rewriting codes. By adding a new method, prepare a backup access path.