Help protect children from gaming harms.

Take our survey

Please or to access all these features

Chat

Join the discussion and chat with other Mumsnetters about everyday life, relationships and parenting.

Ocado now wants a One Time passcode for me to shop

44 replies

TemuSussex · 21/07/2026 08:25

This is annoying, now if I want to login to Ocado, even on trusted devices, I have to check my email for a one time passcode and enter it before I can shop.

I will be letting them know what I think but is anyone else irritated by this?

OP posts:
Erin1975 · 21/07/2026 08:34

You are complaining because a company to which you have given your personal data and your credit card details is implementing decent security measures?

Luckyforsome23 · 21/07/2026 08:36

I fixed this by adding my card to paypal and linking my paypal to Ocado.

Growlybear83 · 21/07/2026 08:36

I’ve never been asked for a one time password for my Ocado account and I log into the app several times each week.

MistakenFlutterby · 21/07/2026 08:38

They are doing it for your benefit, to stop your bank details from being stolen.

It’s annoying but much less annoying than paying for someone else’s groceries or having your bank details or identify stolen.

DontCallMeBaby · 21/07/2026 08:39

We had a palaver on last order - insisted on a change of password when DH went to use it. I had to do that and then reshare the password … I’m all for security but not keen on a forced change.

DD refused to logout and back into use the new password, and then messaged me later in the day asking for the OTP. But not the new password funnily enough.

So trying to improve security but very clumsy. Email 2SV is pretty crap and every interaction, if that’s what they’re doing, is overkill. Esp for a service that is going to be shared - three of us make and amend orders, and a huge part of the appeal of online grocery shopping is we can do that entirely independently of each other.

2SV should be for significant stuff like changing the delivery address, not making changes to an order on a trusted device.

TemuSussex · 21/07/2026 08:41

My payment details are already encrypted. Even I can't view my own card number if I login and they will be storing them in a PCI compliant way. I already have a password.

So yes, I am irritated. God it's so adversarial on here these days!

OP posts:
PrettyLittleRose · 21/07/2026 08:42

And this is a problem because............ ???

I have to have a new one-time passcode (PIN) half the time I log into my banking online, and most of the time I log into the NHS app. Better that than people accessing my personal details!

.

TemuSussex · 21/07/2026 08:42

DontCallMeBaby · 21/07/2026 08:39

We had a palaver on last order - insisted on a change of password when DH went to use it. I had to do that and then reshare the password … I’m all for security but not keen on a forced change.

DD refused to logout and back into use the new password, and then messaged me later in the day asking for the OTP. But not the new password funnily enough.

So trying to improve security but very clumsy. Email 2SV is pretty crap and every interaction, if that’s what they’re doing, is overkill. Esp for a service that is going to be shared - three of us make and amend orders, and a huge part of the appeal of online grocery shopping is we can do that entirely independently of each other.

2SV should be for significant stuff like changing the delivery address, not making changes to an order on a trusted device.

100% agree! Dh accesses the account as well.

OP posts:
DontCallMeBaby · 21/07/2026 08:44

They’re not good security measures if they make the service unusable.

And if anyone is using a service where you can just log in and see your full credit card details suggest you delete those details and stop using that service immediately.

Banking and NHS apps entirely different to shopping.

Mcdhotchoc · 21/07/2026 08:48

It's intensely irritating but it's the only way to protect systems currently

Darragon · 21/07/2026 09:01

MistakenFlutterby · 21/07/2026 08:38

They are doing it for your benefit, to stop your bank details from being stolen.

It’s annoying but much less annoying than paying for someone else’s groceries or having your bank details or identify stolen.

And precisely how many times has that actually happened to you before they implemented this nonsense? I hate this myth that passwords are not secure. The reality is, we’re all having our time and bandwidth wasted with increasingly preposterous security measures to nanny the people in the world whose passwords are all a variation on the word Password, their name, or something else easily guessable, who use the same password everywhere, and who expect a refund when they get robbed because they are too stupid for the internet (putting prices up for us all). YANBU to be annoyed OP, I’m so fed up of it all.

ChippyDinner · 21/07/2026 09:03

Maybe they’ve seen some suspicious activity on your account, I’ve never had that and use Ocado twice a week

LastTrainsEast · 21/07/2026 09:06

Ocado was hacked recently and this is probably their reaction and it is very annoying.

But that should not be possible in the first place. The username/password encryption is supposed to make that impossible, but time and time again we find we have to jump over hurdles so that companies can leave our details out in the open for anyone to read.

It's implemented badly so I can't even trust a device.

But hey maybe they have a point there. After all if a gang breaks in, ties me to a chair and forces me to unlock my phone then they'd be able to order anything they like... without.. waiting.. for an email... ah yes doesn't help in that case does it. 😁

LastTrainsEast · 21/07/2026 09:10

For those who have not experienced this yet I gather that it is being gradually brought in. It was implied but Ocado waffled a lot so it was hard to be sure.

DontCallMeBaby · 21/07/2026 09:23

It’s security theatre at best. They need to protect high risk stuff - like changing address or adding a new one. That’s a real thing that could happen if someone had my username and password, they could log in and send hundreds of pounds worth of stuff to their address. They can’t see my credit card details, they can’t see my password, they can’t change my password.

somekindof · 21/07/2026 09:24

on my account it seems to ask for the one time passcode at check out when I have spent over a certain amount (maybe 250), that seems to make the extra layer of security kick in

DontCallMeBaby · 21/07/2026 09:32

Nowhere near that amount when DD needed a code. I presume this is what it’s about: https://www.mumsnet.com/talk/shopping/5515591-ocado-hacked-if-you-are-a-customer-please-change-passwords-asap

I only now realise I ‘have’ a Ocado Zoom account as it’s accepting my Ocado username and recently changed password. Requires the OTP though - which is a good use of one.

The flaw in the hack though is having a whole different service that you don’t even know exists but uses existing credentials, presumably allowing login without OTP at that point and THEN allowing a change of address without verification plus high value and suspect orders.

OCADO hacked- if you are a customer please change passwords asap | Mumsnet

It looks like Ocado has been hacked, there are a number of reports on trustpilot and also news reports in the last 2 weeks or so of customers finding...

https://www.mumsnet.com/talk/shopping/5515591-ocado-hacked-if-you-are-a-customer-please-change-passwords-asap

Yamyamabroad · 21/07/2026 09:47

I haven't had that but get asked to verify my payment on the banking app every time I do something - even if I'm adding a voucher and reducing the spend. I know its for security but its annoying when there are two of you in the house and the other one has to verify. It has effectively meant that DH is the only one that can add items to the shop.

Lentilcakes · 21/07/2026 12:10

This is exactly what they should be doing. You’re aware of cybersecurity?

Crummles1 · 21/07/2026 19:13

It is very irritating, I agree

No forewarning or explanation was given

DontCallMeBaby · 21/07/2026 20:24

Lentilcakes · 21/07/2026 12:10

This is exactly what they should be doing. You’re aware of cybersecurity?

It’s BAD pointless performative cyber security. One of the purposes of 2-step verification is to prevent someone being able to change all your passwords on all your accounts. A code sent to your email doesn’t do that - email-based 2SV is verging on useless.

What they should be doing is implementing passkeys. SMS or app-based 2SV for high risk activity. All the while considering the reality of how people use their service - not pushing the security burden onto their customers and reducing usability.

TemuSussex · 21/07/2026 20:56

Lentilcakes · 21/07/2026 12:10

This is exactly what they should be doing. You’re aware of cybersecurity?

I am, are you aware you’re being patronising?

OP posts:
Crummles1 · 21/07/2026 23:11

@ DontCallMeBaby

I don't really understand what you mean but I think I agree with you 😅

Aloren · 21/07/2026 23:24

I'm having this problem too and it's really shit.

If I was trying to add a new address, then I could understand it. But why do I have to jump through this pointless hoop to get groceries delivered to my own verified home address? Are those devious cybercriminals planning to send me milk and Hob-Nobs without my consent?

thiswillbedisplayedwhenyoupost · 22/07/2026 12:07

I will just start shopping in shop instead by the time I have put my pin into my laptop, my password onto my account my onetime code to make the payment I could have gone to the shops. I have anti malware installed, I have passwords aplenty. All to add an extra loaf on my order. My it guy said its all just for show, if the hackers want you they will get you.

Swipe left for the next trending thread