One-Time Password (OTP)
A one-time password is a code valid for a single login or transaction, delivered by SMS, app, or token — stronger than static passwords, but phishable.
A one-time password (OTP) is an authentication code that is valid for a single login attempt or transaction, after which it expires. OTPs are the most common second factor in multi-factor authentication: the familiar six digits that arrive by SMS, appear in an authenticator app, or scroll across a hardware token.
How it works
OTPs come in two main flavors. Time-based codes (TOTP) are generated from a shared secret and the current clock, refreshing every 30 or 60 seconds inside an authenticator app or token — nothing is transmitted, so there is nothing to intercept in transit. Delivered codes, by contrast, are generated server-side and sent to the user over a channel, most often SMS or a voice call. That delivery channel is where the security of the whole scheme is decided: an app-based code lives on a specific device, while an SMS code goes to whoever currently controls the phone number.
Attackers exploit that difference in three ways. SIM swapping moves the victim's number — and every SMS code — onto the attacker's SIM. Real-time phishing pages and adversary-in-the-middle kits simply ask the victim to type the code and relay it to the real site within its validity window. And OTP bots automate the ask entirely, placing convincing robocalls that talk victims into reading codes aloud.
How to defend
Treat OTPs as a hierarchy, not a checkbox. Retire SMS and voice delivery first — they inherit every weakness of the phone number, as our guide to SIM swapping attacks details. App-based TOTP is a solid middle tier for general users, though any code a human can read, a human can be tricked into sharing. For administrators, executives, and finance roles, move to phishing-resistant MFA — FIDO2 keys and passkeys — where there is no code to steal, relay, or read out loud. And train the one rule that covers every variant: no legitimate process ever requires you to tell another person your code.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo