Zimbabwe Scam Watch · 8 min read
Facebook Marketplace ‘Verification Code’ Scam in Zimbabwe: Never Read Back an OTP
A buyer asks for a code to prove you are real. The code may actually approve an account action. The Zimbabwe-safe rule is simple: no buyer, seller or support agent needs your OTP.
A Marketplace buyer can sound unusually careful: ‘There are too many fake sellers. I just need to verify that you are real. I sent you a code—please read it back.’ That request feels like buyer protection. It can actually be the takeover step.
The source video describes this tactic on Facebook Marketplace. The exact service behind the code can vary. The FTC has documented a closely related Google Voice verification scam in which criminals target people selling goods online and ask them to hand over a code. Other versions use password resets, login approvals or phone-number registration.
For a Zimbabwean seller, the safest rule is broader than any one platform: if a code arrives because somebody else initiated something, do not give them the code.
How the Scam Works
The attacker first needs a believable reason to make you cooperate. A Marketplace listing gives them your attention and often your phone number. They then trigger a legitimate verification or recovery process on another service.
You receive a genuine SMS or app notification. That is what makes the scam convincing: the message itself can be real even though the person asking for the code is a criminal.
The attacker says the code proves you are genuine. In reality, the code may prove to Google, Facebook, an email provider, a bank, a mobile-money service or another account that the person entering it is authorised.
The mistake is not necessarily clicking a fake link. The mistake is turning a private authentication factor into a message you give to a stranger.
What This Looks Like in Zimbabwe
A local version can begin with a phone, laptop, Starlink kit, vehicle part, furniture item or business equipment listed on Facebook Marketplace or in a WhatsApp group. The conversation quickly moves to WhatsApp because that feels normal.
The buyer may say:
- ‘Send the code so I know the number is yours.’
- ‘I need to verify you before I send EcoCash.’
- ‘Facebook sent you a seller verification code.’
- ‘I accidentally used your number; just tell me the OTP.’
- ‘Customer support needs the code to release payment.’
None of those explanations changes the control: do not disclose the code. EcoCash’s terms are especially clear: customers must keep their PIN and one-time PIN secure and must not disclose them even to call-centre staff, agents or partner-bank staff.
The 30-Second Defence
- Never read an OTP back to a buyer.
- Read the SMS carefully; it often says what action the code authorises.
- Do not move to a new ‘support’ contact supplied by the buyer.
- Open the relevant app yourself rather than using a link from the conversation.
- Use different passwords for Facebook, email and financial accounts.
- Where available, prefer an authenticator app or hardware key over SMS for important accounts.
A useful mental model is simple: password = something you know; OTP = something you temporarily possess. Giving away either can defeat the login barrier.
If You Already Shared the Code
Act as though the account may be compromised. Change the password on the account named in the OTP, sign out other sessions, review recovery email and phone settings, and secure the email account behind your social profiles. If the code involved EcoCash, banking or your SIM, contact the provider through an official channel immediately.
Do not spend time arguing with the ‘buyer’. Recovery speed matters more than proving the scammer wrong.
Frequently Asked Questions
Can a real buyer ever need the OTP sent to my phone?
Not to prove that you are a genuine seller. A one-time code is normally for the account or transaction process that generated it. Do not disclose it to another user.
What if the SMS itself is genuinely from Google, Facebook, EcoCash or my bank?
That can make the attack more dangerous, not safer. The criminal may have triggered a genuine security process and now needs the legitimate code that only you received.
What should I do if I already sent the code?
Immediately secure the named account, change passwords, review sessions and recovery settings, and contact the relevant provider if money, your SIM or a wallet may be involved.
Sources & further reading
- New Scams That Look Completely Real Now — Chill Dude Explains
- The Google Voice scam: How this verification code scam works and how to avoid it — U.S. Federal Trade Commission
- EcoCash Terms and Conditions — EcoCash Zimbabwe