Bewary Get Bewary
Shared code Published Sep 15, 2026

Who texted me from 22395?

Bewary fraud research, published by Andrey Khayrullaev, founder. How we research scam patterns.

Example text from 22395

Your Authy verification code is: 483921

MIXED

22395 is legitimate, but shared. Twilio leases this short code for Verify and Authy one-time passcodes, so 22395 can carry codes for many different apps and services. Judge the message by its shape: a passcode tied to a sign-in, checkout, account setup, or Authy verification step you started. The danger starts when someone triggers that genuine code and then pressures you to read it back.

Operated byTwilio

What real messages from 22395 do

  • Use 22395 when a Twilio-backed app just asked to verify your phone.Why
  • Type the 22395 code into the same screen that requested it.Why
  • Read the brand name in the text before using the code.Why
  • Treat an unrequested 22395 code as a sign someone tried your number.Why
  • Expect a short passcode message, not a recovery campaign.Why

How a fake 22395 differs

  • Hang up when a caller asks for the 22395 code.Why
  • Check the sender line before trusting the number in the text.Why
  • Do not tap a link that rides with a 22395 code claim.Why
  • Stop when a charge story appears before the code request.Why
  • Reject any reply request that includes the passcode.Why
  • Stop if the brand in the 22395 text does not match your screen.Why
  • Change the account password if a caller says to leave it alone.Why
  • Do not trust a caller just because the timing is perfect.Why

What to do now

  1. Keep the 22395 code inside the Twilio prompt that produced it.Why
  2. End any call or chat that asks you to read the code.Why
  3. Open the named account from your saved app and change the password.Why
  4. Remove new recovery methods from the account.Why
  5. Send 22395 abuse details to Twilio at spam@twilio.com.Why
  6. Forward ordinary-number impostor texts to 7726.Why

Got a text you are unsure about?

Paste it here. Bewary reads it and tells you straight, free.

22395 in detail

The reasoning behind each line above, for when the immediate question is settled.

What real 22395 messages are for

Use 22395 when a Twilio-backed app just asked to verify your phone.

The same short code can serve more than one company because Twilio runs shared Verify and Authy traffic. The brand name belongs in the message body, while 22395 is only the delivery channel.

Type the 22395 code into the same screen that requested it.

Genuine traffic from this code finishes a step already open in front of you, such as an Authy setup, app sign-in, checkout verification, or phone-number check. The code is a one-time passcode, so the value is the secret.

Read the brand name in the text before using the code.

A Twilio Verify message usually names the service that caused the code, often in a plain line like “Your Authy verification code is: 483921.” If the service name does not match the screen you are using, stop the flow.

Treat an unrequested 22395 code as a sign someone tried your number.

The SMS can be generated by Twilio and still be part of an account-takeover attempt. A thief may be testing a password, starting a reset, or trying to enroll your number on an account.

Expect a short passcode message, not a recovery campaign.

22395 is used for one-time code delivery, not long fraud alerts, refund pitches, debit-card warnings, or crypto withdrawal notices. Extra drama around the code usually belongs to the person trying to steal it.

Where an impersonation of 22395 gives itself away

Hang up when a caller asks for the 22395 code.

The live scam is simple: the caller starts a login or reset, Twilio sends the passcode, then the caller claims they need those digits to cancel the attempt. Reading it out lets them pass the check as you.

Check the sender line before trusting the number in the text.

A ten-digit sender can write “Your 22395 code is 184006” inside the body, hoping you remember the short code and ignore where it came from. The sender line tells you whether the SMS actually came through 22395.

Do not tap a link that rides with a 22395 code claim.

A fake may use a lookalike such as authy-verify22395[.]com and say the code expires unless you sign in there. Twilio’s OTP job is to deliver the passcode, while the login page should already be open.

Stop when a charge story appears before the code request.

The caller may claim a pending Shop Pay order, brokerage transfer, or wallet withdrawal will go through unless you confirm the 22395 digits. Verification codes do not reverse payments when spoken over the phone.

Reject any reply request that includes the passcode.

A fake text may say “reply CANCEL 483921” or “send the code to close this request.” The secret belongs in the app or site field that requested it, not in an SMS reply to a stranger.

Stop if the brand in the 22395 text does not match your screen.

If you are setting up Authy and the text names a trading app, someone else may have started a flow using your phone number. Shared Twilio infrastructure explains why the same short code appears, but it does not explain a brand mismatch.

Change the account password if a caller says to leave it alone.

Scammers use lines like “do not change anything while we investigate” because a password change can cut off their attempt. An unexpected 22395 code means you should assume the named account is being tested.

Do not trust a caller just because the timing is perfect.

Attackers can trigger the code while they are on the phone, then act like the instant SMS proves they are support. The timing proves only that someone started a verification flow.

Working through the steps

Keep the 22395 code inside the Twilio prompt that produced it.

If you started the sign-in, checkout, Authy setup, or phone check, finish it in that same window. Do not move to a link or script introduced after the SMS arrived.

End any call or chat that asks you to read the code.

Close the conversation before arguing. The person asking for the digits is trying to complete a verification step from their side.

Open the named account from your saved app and change the password.

Do this when the 22395 code arrived without your action, or when a caller contacted you about it. Check recent sessions and sign out devices you do not recognize.

Remove new recovery methods from the account.

Look for added phone numbers, backup emails, authenticator apps, passkeys, and trusted devices. A stolen passcode is often used to add a second way back in.

Send 22395 abuse details to Twilio at spam@twilio.com.

Include the full SMS text, the time received, the brand named in the body, screenshots, and what the caller asked you to do. Use this route for abuse involving Twilio’s short-code channel.

Forward ordinary-number impostor texts to 7726.

Use this when the sender was a regular mobile number pretending to be 22395 in the message body. After forwarding, block the number and keep the screenshots if money moved or an account changed.

Sources

What this page checks against.