Practical guide
Verification Codes Are Not Support Ticket Numbers
Recognize when a helpful-sounding request is asking for a secret that belongs only in your own sign-in process.
Read what the code message says
A person in a chat asks you to read back a number that just arrived on your phone. Before responding, read the message containing that number. Does it describe a sign-in, recovery, or account change that you personally started? A code is not made harmless by calling it a ticket reference or identity check. Keep the code inside the verified process it belongs to. If the request and the message describe different actions, stop instead of accepting the person's explanation over the screen.
Distinguish references from credentials
A support ticket number helps identify a conversation. A verification or recovery code may help authorize access. You should not have to guess which kind of number you are sharing. For example, a ticket reference can be read from a support confirmation, while a message saying that a code is for sign-in describes a different purpose. Google's backup-code documentation explicitly tells users not to share those codes. Treat any unclear secret as private until the official process makes its purpose understandable.
Do not split a secret to make it feel safe
Someone may ask for only part of a code, request a screenshot with the number visible, or say that the number will expire too soon to matter. These variations do not create a useful privacy boundary. You would still be giving account-related material to an unverified recipient. Reply with a description of the problem rather than the code itself. If the person genuinely represents support, they can explain a documented recovery route that you perform through the service, not through their personal message thread.
Recover through the real account channel
If you shared a code, stop the conversation and review the account using the provider's official recovery or security process. Be accurate about the kind of code and the time it was shared; do not send the same code to more people while asking for help. Keep a nonsecret incident note and check for unfamiliar account changes. The takeaway is a simple classification habit: reference numbers describe a task, while authentication secrets can authorize one. Do not let a helpful tone erase that difference.
Sources checked
Linked reference pages checked on 2026-09-09. Product details can change. No paid-membership test or sponsorship is implied.
Google Account Help: keeping backup codes private ↗