What Details Should I Never Share?
You should never share passwords, full card numbers, or one-time security codes by email, text or unexpected call.
In this answer
- Identify the details that should stay private
- Understand why these details are sensitive
- Learn how to share information safely when needed
- Recognise requests that should raise concern
- Know what to do if you have over-shared
4 min
Details to keep private
Some information should almost never be shared, especially in response to an unexpected message or call. Keeping a short mental list of these makes it much easier to recognise when a request has crossed a line that a genuine process would never ask you to cross.
- Online banking passwords or PINs.
- Full card numbers, with the expiry and security code together.
- One-time passcodes or verification codes sent to your phone.
- The answers to your security questions.
These details can give someone direct access to your money or your accounts, often before you notice anything is wrong. A genuine business designs its processes so it never needs you to reveal them in full by email, text, or an unsolicited call. If you are ever asked to, treat the request itself as the warning sign, regardless of how official the message appears.
Why these details matter
Passwords, codes and full card numbers are effectively the keys to your accounts and your money. If they fall into the wrong hands, they can be used to make payments or take over an account quickly, sometimes before you have any chance to react. That is precisely why legitimate organisations build their systems so they never need you to hand these over in full, and why a request for them is so out of place.
One-time codes deserve particular care. They are meant for you alone, to complete a single login or payment, and no genuine caller should ever ask you to read one out. If someone does, that is one of the clearest signs of a scam there is, and the right response is to refuse and verify independently. Understanding why these details are so sensitive makes it far easier to hold the line when a convincing message tries to talk you out of it.
Sharing information safely
There are times when you will legitimately need to confirm some details, for example when verifying your identity at the start of a conversation about your matter. The safe approach in those moments is to share only what is genuinely necessary, and only through a channel you have confirmed for yourself is real, rather than one offered to you in an unexpected message.
If you are unsure whether a request is legitimate, stop and verify first by contacting the business through details you look up yourself. For a matter with Merion, you can reach us through our official website and confirm the request before you respond to it. Our guidance on identity verification explains what reasonable checks involve, so you can tell a proportionate request apart from one that asks for far too much.
If you have shared too much
If you think you have shared a password, a code, or your card details with someone you should not have, act promptly rather than waiting to see what happens. Change any affected passwords, contact your bank or card provider, and keep a close watch on your statements for activity you do not recognise. Quick action is what limits the impact, and the first hour often matters most.
You can report scams that tricked you into sharing information to Scamwatch at scamwatch.gov.au, which also helps protect other people from the same approach. There is genuinely no need to feel embarrassed, because these tactics are carefully designed to catch people off guard, and even cautious people are sometimes caught. What matters now is responding quickly and methodically, not how the situation arose.
Key takeaways
- Never share passwords, PINs, full card details or one-time codes by message
- No genuine caller asks you to read out a verification code
- Share only what is necessary, through channels you have confirmed
- If you over-share, change passwords, call your bank and report it
Frequently asked questions
Why should I never read out a one-time code?
One-time codes are meant for you alone to complete a login or payment. A genuine business will never ask you to share one, so any such request is a warning sign.
What if I need to confirm my identity?
Share only the minimum needed, and only through a channel you have confirmed is genuine. Reasonable verification does not require your full passwords or codes.
I shared my details by mistake. What now?
Change affected passwords, contact your bank, monitor your accounts, and report it to Scamwatch. Acting quickly helps limit any impact.
Fair, professional, compliant — always
Merion handles every account on the facts, with respect, and within the rules. Questions? We're happy to help.