You received a password-reset code or link you did not request
A single message may be a mistake, but you should not click it or share the code. Here is a calm way to check whether the account is safe.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 5 September 2026
- READING TIME
- 7 min read
- TOPIC
- Identity and Access
A six-digit code arrives on your phone. Moments later, your inbox shows a “reset your password” message. You did not request anything. The first thought is that somebody is already in the account. The second is to click quickly and find out.
Neither panic nor clicking is necessary. A reset message alone does not prove account takeover. Google explains that another user may have entered the wrong email address and that an unrequested assistance message does not compromise the account. Microsoft lists several possibilities: an attempted sign-in, a typing error or delayed delivery of a code requested earlier.
The most important rule: keep the code to yourself
Do not reply and do not give the code to anyone. A caller who appears moments later as “technical support” does not need it to cancel an operation. The code confirms an action; it does not stop one.
Do not use the message link to inspect the account. Even if the first notification was genuine, another message could be phishing disguised as a security response. Open the familiar app or type the service address into your browser yourself.
A five-step check
- Open the account through an independent route. Do not use a button in the text message or email.
- Review recent activity and signed-in devices. Look for unfamiliar locations, devices and setting changes.
- Check recovery details. An unknown phone number or email address requires immediate action.
- Decide whether this is one message or a pattern. One may be an error. Repeated codes, sign-in notices or account changes raise the risk.
- For a work account, report it to IT. Give the time, service and notification type; do not forward a live code.
If the account shows no unfamiliar activity, the password is unique and there was only one request, ignoring it will often be enough. Microsoft emphasises that a person attempting access cannot complete the step without the code.
When to change the password
Change it when you find an unfamiliar sign-in, an unrequested setting change, repeated attempts, or have reason to believe the current password was exposed or reused elsewhere. Use the official site, then close sessions you do not recognise.
The new password should be unique to that account. A password manager prevents one breach from opening email, shopping and social media at once. Enable another factor or a passkey where available, and store recovery codes somewhere safe.
If the notice says the password has already been changed, rather than merely requesting a reset, treat it as an urgent incident. Use the official recovery process, check the email account and close active sessions. For a company account, do not handle it alone.
Beware the conversation that follows
An attacker may start a genuine reset and then call, using the real code to support a convincing story. They may know your name, employer and part of your phone number. None of those details changes what the code is for.
A flood of sign-in approval prompts uses the same human weakness: someone hopes you will press a button for peace and quiet. If you see repeated app prompts instead of a code, deny them and follow our guide to an unexpected MFA notification.
Source facts and Breachroad’s conclusion
The possible reasons for an unrequested message and the advice not to share a code come from official Google and Microsoft guidance. The five-step check, distinction between a request and a completed change, and independent-channel rule are Breachroad recommendations.
Not every notification means a breach, but every one deserves the same calm response: avoid the received link, keep the code private and inspect the account directly. Our guide to rolling out MFA covers wider access protection. Cybersecurity training for employees lets teams rehearse this moment before a real caller starts applying pressure.


