One-time passcodes — the six-digit texts from your bank, Google, or Amazon — exist to stop someone who has your password from getting in. Which means scammers who have your password (breaches leak billions) have exactly one problem left: the code on your phone.
They can't intercept it. So they call you and ask for it.
The scripts they use
'This is your bank's fraud team — to verify your identity, read me the code we just sent.' The code was triggered by the scammer on the real login page. Reading it back logs them in.
'I'm a buyer from the marketplace listing — I need to verify you're not a bot, I texted you a code.' That's a Google Voice code; sharing it gives the scammer a phone number registered to your identity, which they use to run scams that trace back to you.
'Your account will be closed unless you confirm the verification code.' Urgency plus a code request, in any wrapper, is the same attack.
The rule and the recovery
The rule is absolute and easy to remember: codes are for typing into websites and apps, never for telling a person. No bank employee, no support agent, no buyer, no government agency will ever legitimately ask you to say a code out loud. Anyone who does is an attacker mid-break-in.
If you already shared one: change that account's password immediately, log out all sessions, check for changed recovery emails or forwarding rules, and re-enable two-factor. If it was a bank code, call the fraud line now — you may be minutes ahead of a transfer.
