They can't just change the verification code, and it's not based on the fields of the contact card. You can think of it as a fingerprint for their iMessage public key, the one used to encrypt messages end-to-end. If the key with which your phone encrypts iMessage payloads has changed, it indicates that the conversation is being intercepted.
WhatsApp supports this too, see "Verify Security Code" on this page: https://faq.whatsapp.com/820124435853543
So does Signal: https://support.signal.org/hc/en-us/articles/360007060632-Wh...
So does Telegram: https://telegram.org/faq#q-what-is-this-39encryption-key-39-...