VendaVault Join The Movement
Potted cactus, succulent, and leafy plant on a white table beside a grey sofa with cactus-print cushions.
Card Safety & Tokenization 5 min read · June 6, 2026

Your bank just asked for an OTP — what to do (and what not to)

VendaVault Team
VendaVault Team
June 6, 2026
5 min read

When your bank asks for an OTP, what to do next is the most common moment of panic in modern Caribbean banking. Your phone buzzes, your bank's app shows a six-digit code, the message says "this code expires in 5 minutes," and there are two possibilities: either you just tried to make a purchase and this is the normal challenge, or someone else just tried to make a purchase with your card. The action you take depends on which one it is.

This article walks through the four scenarios in order of likelihood, what to do in each, and how to set up your VendaVault so the OTP moments become predictable rather than scary.

When the bank asks for an OTP: was it you?

The first question is the only question that matters: did you just initiate a payment, log in, or change something on your bank account?

Yes, it was me. Enter the code where the app asked. This is 3-D Secure (3DS) — the issuer-side check that confirms you, not just your card, authorized the purchase. It is normal, it is good for you, and it is the reason card-not-present fraud has dropped sharply across the Caribbean since 2023.

No, it was not me. Do three things in order, and do them in this order specifically:

  1. Do not enter the code anywhere. The code is the key to the vault; if you give it to a fraudster, they own the transaction.
  2. Open your bank's app and check the recent activity. The pending transaction will be there with a merchant name.
  3. If you recognize the merchant (auto-renewing subscription you forgot about, a hotel hold, your spouse) — fine, enter the code. If you do not, call your bank's fraud line, the number is in the same app.

Bank OTP what to do when you cannot decide

Sometimes you are not sure. The most common version: the OTP arrives twenty minutes after you actually tapped your card, because the merchant batched the authorization. Or the merchant's name on the OTP is the parent company's name, not the shop you used (e.g., the OTP says "STRIPE PAYMENTS" but you actually paid a small online vendor whose processor is Stripe).

When you cannot decide:

  • Wait the full five minutes. The OTP will expire. If a real fraudster initiated the transaction, they will retry — which gives you a second OTP and confirms it is not your old, batched authorization arriving late.
  • Do not enter the code under pressure. A real bank OTP does not require speed. A scammer pretending to be your bank will rush you. Time pressure on the phone is the single best signal that the call is fraudulent.
  • Call the number on the back of your card or in your bank app. Never the number a caller gives you over the phone. The fraudster's playbook is "we will help you — what was that code?" The fraudster needs the code; the bank does not.

The most common scam, in plain language

A common Caribbean phone scam in 2026: someone calls you claiming to be from your bank's fraud department. They tell you a fraudulent charge has been attempted, they need to verify your identity, and they will send you an OTP. They then ask you to "read the OTP back to them to confirm your identity." The moment you read it back, they enter it into a transaction they just initiated, and the money is gone.

The bank will never ask you to read an OTP back over the phone. If the call is from your bank, they have already verified your identity by other means before reaching you. The OTP is for your screen, not their ears. If anyone on a call asks for an OTP, the call is a scam. Hang up.

How your VendaVault makes this easier

VendaVault initiates the 3DS challenge inside the vault's own app, with the OTP shown in-app rather than as a separate text message. That means:

  • You see the merchant name and amount on the same screen as the code. No more "is this the right transaction?" guesswork.
  • The code auto-fills inside the vault — no copying digits between apps.
  • You see your transaction history right there, so a stale OTP from earlier today is obvious.

This is one of the practical changes that makes the OTP moment a non-event rather than a worry. The bank OTP what to do question stops being a riddle when the OTP is shown next to the transaction it authorizes.

Three rules of thumb

  • An OTP is for your screen, never for anyone else's ears.
  • If you did not just initiate a transaction, do not enter the code.
  • Time pressure on the phone is the single highest signal a call is fraudulent.

That is the bank OTP what to do framework in three sentences.

Open your vault

If you have not set up your VendaVault yet, the OTP-handling improvements above are part of what changes the moment you do. Three minutes at vault.vendapay.net/register, link the card you use most, and the next OTP that arrives makes more sense than any OTP you have ever read. Open your VendaVault →

Continue reading