
Martin Lewis Phone Security Code – Never Share With Anyone
Phone security codes have become the final barrier between criminals and empty bank accounts. Martin Lewis, founder of MoneySavingExpert, has issued stark warnings that sharing these digits—often sent via text as two-factor authentication—destroys that protection instantly. His campaign emphasizes a simple rule: legitimate banks never ask for these codes, and treating them with the same secrecy as your PIN is now essential consumer defense.
The urgency reflects a surge in sophisticated fraud where criminals impersonate bank staff or trusted services. These scammers exploit urgency and authority to extract codes from unsuspecting victims. Once shared, account takeovers happen within minutes, often leaving victims with drained savings and little recourse.
Lewis has amplified this message through his ITV Money Show appearances and MSE platform, responding to viewer concerns about phone theft and banking safety. The advice extends beyond code secrecy to include practical steps like securing device identifiers—critical knowledge as phone snatching rises across the UK.
Why Does Martin Lewis Say Never to Share Your Phone Security Code?
- Sharing a security code grants criminals immediate access to bypass your password and biometric protections
- Fraudsters often pose as bank fraud departments to create false urgency and trust
- Biometrics alone cannot protect bank apps if a thief gains physical possession of your unlocked phone
- MSE and Action Fraud joint campaigns documented millions in annual losses from code-sharing scams
- The Metropolitan Police seized 1,000 phones in February 2025, highlighting the scale of device theft enabling these frauds
- Lewis’s advice extends to saving your IMEI number (*#06#) to help police block stolen handsets across networks
| Fact | Detail |
|---|---|
| Primary Warning | Never give your security code to anyone, “not even to your bank” |
| Source Authority | Martin Lewis, MoneySavingExpert founder and ITV presenter |
| Risk Level | Full account access and unauthorized transactions within minutes |
| Campaign Period | Ongoing since 2022, with peak warnings during 2024-2025 |
| Associated Threat | Phone theft (78,000 cases in England/Wales to March 2024) |
| Verification Method | Legitimate banks never request 2FA codes via phone, text, or email |
| Reporting Channel | Action Fraud (UK’s national fraud reporting center) |
| Device Protection | IMEI retrieval (*#06#) to enable police blocking of stolen devices |
What Is a Phone Security Code and Why Is It Dangerous?
What is a phone security code?
A phone security code—typically a six-digit number sent via SMS or generated by an authenticator app—serves as the second layer of verification in two-factor authentication (2FA). When you log into banking apps or authorize payments, this code proves you possess the registered device. Banks generate these codes automatically during sensitive transactions, sending them only to the mobile number linked to your account.
Why is sharing a security code dangerous?
The danger lies in the code’s function as proof of identity. When you share it, you effectively hand over the keys to your account. Scammers exploit this by posing as bank security teams claiming to detect suspicious activity. They create panic, request the code to “verify your identity” or “stop a transaction,” then use the code to empty accounts or authorize fraudulent transfers. According to reports on Lewis’s warnings, this tactic has led to millions in losses through authorized push payment (APP) fraud.
Once you share a 2FA code, criminals can bypass passwords and biometric locks entirely. The code operates as temporary proof that the possessor is the legitimate account holder, granting immediate access to transfer funds or change account details without further verification.
What Scams Involve Asking for Your Bank Security Code?
The fake fraud department call
Scammers spoof bank phone numbers to appear legitimate on caller ID. They claim your account shows suspicious transactions and ask you to read back the “verification code” just sent to your phone—actually a code triggered by their login attempt. Action Fraud documentation confirms these imposters often know partial account details obtained through data breaches, enhancing their credibility.
Smishing and urgent text messages
Text messages claiming your account is frozen or compromised direct you to call a number or reply with security codes. The messages mimic bank formatting exactly. Lewis emphasizes through MSE that banks never request codes via SMS responses or inbound calls.
Device theft follow-up
With 78,000 phone thefts reported in England and Wales through March 2024, criminals have adapted. Stolen devices provide access to banking apps, but biometrics often block immediate entry. Thieves call the stolen phone posing as “bank security,” claiming they need the code to secure the account, tricking victims who don’t yet realize their phone is stolen.
How to Protect Yourself from Phone Code Scams According to Martin Lewis
Enable layered biometric protection
Lewis advises that fingerprint or Face ID protection must apply to both your phone lock screen and individual banking apps. As noted in his recent guidance, biometrics on the phone alone are insufficient if thieves bypass the lock screen through shoulder-surfing or coercion.
Secure your IMEI number immediately
Dial *#06# on your phone to reveal its unique 15-digit IMEI identifier. Screenshot or record this number securely—never on the device itself. If your phone is stolen, providing this to police enables them to block the handset across all UK networks, rendering it worthless to criminals and protecting any cached banking sessions.
Store your IMEI separately from your phone. Enable biometric locks on every banking app. Never answer security questions or provide codes during unsolicited calls—instead, hang up and contact your bank using the number on your card.
Verify through independent channels
If someone claims to be from your bank, terminate the call and dial the number on the back of your card. Wait five minutes or use a different phone to ensure the line has cleared, as scammers sometimes stay connected to spoof dial tones. The Financial Conduct Authority supports this verification approach as standard security practice.
If you share a code or suspect compromise, contact your bank immediately to freeze accounts. Report the incident to Action Fraud and Gov.uk fraud reporting. Swift reporting increases the chance of freezing fraudulent transactions before they clear.
For additional consumer protection resources, see our guide on finding Furniture Stores Near Me for secure local shopping alternatives.
How Has Martin Lewis’ Campaign Against Code Sharing Developed?
- : Initial MSE alert launched in collaboration with Action Fraud, flagging 2FA code-sharing as a primary vector for APP fraud.
- : Joint campaigns between MSE and national fraud reporting centers document surge in victims sharing codes with fake bank representatives.
- : Lewis’s warnings gain viral traction through social media, specifically targeting the “never share your code” message amid rising phone snatching statistics.
- : Continued emphasis on the threat, with Lewis responding to viewer Paula on ITV’s Money Show regarding IMEI numbers and post-theft banking security.
- : Metropolitan Police data shows 1,000 phones seized in one month, prompting renewed emphasis on device identification and code security.
- : Statistics confirm 78,000 phone theft cases in England and Wales, reinforcing the link between physical device theft and digital banking fraud.
What Is Certain vs. What Remains Unclear About These Scams?
| Established Information | Information Remaining Unclear |
|---|---|
| Banks never request 2FA codes via phone, text, or email (MSE/FCA verified) | Exact recovery rates for victims who share codes (varies by bank and timing) |
| Sharing codes enables immediate account takeover and unauthorized transfers | Specific jurisdictional success rates for prosecuting code-sharing fraudsters |
| Phone thefts in England/Wales reached 78,000 (year to March 2024) | Projected 2025 figures beyond February’s 1,000-device seizure snapshot |
| IMEI blocking effectively renders stolen phones useless across UK networks | Whether all banks will implement additional verification layers beyond 2FA |
| MSE and Action Fraud ran verified joint campaigns 2022-2024 | Full scope of 2025-specific campaign updates (search limitations prevent full archive access) |
Why Are Phone Security Codes a Critical Issue in UK Banking?
The UK banking sector’s rapid digitization has made 2FA codes the standard gatekeeper for millions of accounts. As transactions migrate to mobile devices, these six-digit numbers represent the final verification step for high-value transfers. Criminals understand that obtaining this code—rather than attempting complex hacks—offers the path of least resistance into secured accounts.
Martin Lewis’s authority on consumer finance amplifies the message’s reach. Through MSE and regular ITV appearances, he reaches demographics that traditional fraud warnings might miss. His specific advice regarding IMEI number preservation addresses the intersection of physical crime (phone theft) and digital fraud, acknowledging that modern scams often begin with a stolen device on the street and end with emptied savings accounts online.
The economic context matters too. With consumer finances stretched, the impact of losing access to 2000 Euros in Pounds equivalent can be devastating for households. This reality drives the urgency behind Lewis’s zero-tolerance stance on code sharing.
What Authorities Support Martin Lewis’ Warnings?
“Never share your phone security code with anyone—not even your bank. If someone asks for it, they are a scammer.”
— Martin Lewis, via MoneySavingExpert and ITV Money Show appearances
Authorized Push Payment (APP) fraud reports indicate victims increasingly approve fraudulent transactions after sharing authentication codes with criminals posing as bank security teams.
— Action Fraud and Which? consumer analysis, 2022-2024
Biometric authentication for banking apps must be enabled separately from device lock screens to prevent unauthorized access following phone theft.
— Martin Lewis technical guidance, ITV Money Show Live
What Is the Key Takeaway From Martin Lewis’ Security Code Advice?
Treat your phone security code as you would the PIN for your bank card—absolute secrecy is the only protection. Martin Lewis’s campaigns reinforce that legitimate institutions will never request these codes, and any request constitutes a scam. Combine this vigilance with practical steps: secure your IMEI number, enable biometric app locks, and verify all unsolicited contact through official channels. In an era where a single six-digit mistake can cost your savings, skepticism is your strongest defense.
Frequently Asked Questions
What if my bank actually asks for the security code?
They won’t. Authentic banks never request 2FA codes during calls, texts, or emails. Any such request confirms you are speaking with a fraudster. Hang up immediately and contact your bank using the number on your card.
Can scammers bypass 2FA without me sharing the code?
Standard 2FA via SMS requires the code to access your account. However, sophisticated attacks may use SIM swapping or malware to intercept codes. Protecting your physical device and IMEI number reduces these risks.
Why did Martin Lewis specifically mention the IMEI number?
The IMEI uniquely identifies your device. If stolen, providing this 15-digit code to police enables them to block the handset across all UK networks, preventing criminals from accessing cached banking apps or selling the device.
Is Face ID alone enough to protect my bank apps?
No. Lewis specifically warns that biometrics on your phone lock screen do not automatically protect individual banking apps. You must enable biometric locks separately within each banking application’s security settings.
What should I do immediately after sharing a code?
Call your bank immediately to freeze your accounts. Report the incident to Action Fraud and Gov.uk’s fraud reporting service. Speed is critical—the faster you report, the greater the chance of stopping fraudulent transfers.
Where can I find Martin Lewis’s latest fraud updates?
Check MoneySavingExpert.com’s weekly email and Martin Lewis’s official social media channels. His ITV Money Show episodes also address current scam trends, though specific broadcast schedules vary.