Hush by Umikflow
← Back to Blog
Authentication4 min read•By Umikflow•Last updated: September 26, 2026

Why Teams Should Stop Forwarding OTPs in Chat

Shared accounts and forwarded authentication codes create serious security gaps. Learn why to avoid them and how to move toward better access control.

The Danger of Forwarding OTPs

One-Time Passwords (OTPs) are sensitive authentication credentials. Although they expire quickly, sending them via Slack, Microsoft Teams, or email normalizes incredibly weak access practices.

When a team gets used to pasting 2FA codes in shared chat channels, they stop questioning the authenticity of access requests, opening the door for social engineering and phishing attacks. Furthermore, retaining authentication codes in chat history creates unnecessary permanent records.

Shared Accounts Are Not Recommended

Shared accounts and forwarded OTPs are insecure workarounds, not a recommended authentication model. They eliminate accountability and break the fundamental security principle of attributing actions to individual users.

Safer Long-Term Alternatives

Organizations should transition away from shared credentials and implement proper access controls: - Individual User Accounts: Every employee should have their own distinct login. - Role-Based Access Control (RBAC): Assign permissions based on an employee's role, not by handing them root passwords. - Single Sign-On (SSO): Centralize authentication to manage offboarding safely. - Shared Authenticators: If a shared account is absolutely unavoidable (e.g., legacy software), use a secure password manager that supports shared OTP generation or an admin-approved workflow, rather than forwarding SMS codes.

Harm Reduction, Not a Solution

If temporary transmission of an authentication code is strictly necessary for an authorized team member during an emergency, tools like Hush can act as a short-term harm-reduction measure. By using a one-time encrypted link, the credential is not permanently recorded in a chat log.

However, Hush does not magically make shared-account access "safe." It is a transmission tool, not a substitute for proper identity verification or access controls.

Frequently Asked Questions

Is it safe to share a 2FA code?
No. You should never share 2FA codes. Legitimate services will never ask you to forward your OTP.
Can Hush verify who opened the link?
No. Hush cannot verify the true identity of the person opening a link. It only ensures the data is transmitted once.

Need to share a secret securely?

Hush encrypts your data in the browser before sending it.

Create a Hush Secret