Another bloody Scam.(Copied from a FB group)
Two-Factor authorisation is the process of requiring secondary authorisation to make a key change such as password or bank details. Banks and other organisations will send a code to an email address or telephone to ensure the genuine user is aware of the change, but fraudsters have identified ways to beat this process.
Fraudsters have been contacting fraud victims purporting to be from the bank/organisation, they state that to verify the call and pass through the security process they will send a 2FA code to the victim.
At the same time, they go through the password reset / bank change process, which automatically sends the code through. They then ask the victim to read the code back to verify their identity, which they can input to the system and bypass the control.
TLDR: NEVER ever give out your password or a 2FA code over email or the telephone.