← all articles

Why SMS 2FA is the weakest option for your accounts

If you have ever logged into a bank or an email account and been asked to type a six digit code that arrived by text message, you have used SMS two-factor authentication. It feels safe. That is the theory.

In practice, text messages were never designed to carry secrets. This article explains what SMS 2FA is, how it breaks, and why I treat it as the last choice on the list, not the first. I am not saying turn it off. I am saying know where it sits.

What it is

Two-factor authentication (2FA) means proving who you are with two different kinds of evidence. The usual split is something you know (a password) and something you have (a phone, a key, an app). A second factor stops an attacker who has stolen or guessed your password, because the password alone no longer opens the door.

SMS 2FA is the version where the “something you have” is a phone number. The service sends a one-time code by text, you type it in, and you are through. Nothing to install, and it works on any handset. That is why almost every service offers it.

Notice what the factor actually is, though. It is not your phone. It is your phone number, which is a routing instruction held by your mobile carrier. Whoever controls where that number points receives the codes. That distinction is the whole story.

How it works

The mechanism is simple, and each step is a place where something can go wrong.

  1. you enter your username and password on a website or app.
  2. the service generates a short random code and hands it to an SMS gateway.
  3. the gateway passes the message into the phone network, which looks up which SIM card currently owns your number.
  4. the message is delivered to that SIM as plain text.
  5. you type the code back in, and the service checks that it matches and has not expired.

Compare that with an authenticator app such as Google Authenticator, Microsoft Authenticator or Aegis. Those apps generate codes on the device from a secret that was shared once, when you set the account up. No code travels over the phone network at all. A hardware key or a passkey goes further and never sends a reusable secret anywhere.

With SMS, the code crosses carrier systems, sits in your messages app, and may show on a lock screen. Three weak points follow from that design:

  • the number can be moved: someone convinces your carrier to attach your number to a SIM they control (SIM swapping), or to port it to another carrier.
  • the message can be read in transit: older telecom signalling protocols such as SS7 were built on trust between carriers, and have well documented abuse paths.
  • the code can be talked out of you: a fake login page asks for the code and passes it to the real site in real time.

Why it matters

Four reasons I rank SMS last, in rough order of how often I see them cause real damage.

Phishing works against it

This is the big one. A fake login page, often built with an off-the-shelf reverse proxy toolkit, shows you a copy of the real site. You type your password, the attacker forwards it to the real service, the real service texts you a code, you type that into the fake page, and the attacker forwards it too. They are now logged in as you, and the code you handed over was valid. SMS cannot tell a real site from a fake one. Neither can a six digit code.

Singapore readers will remember the wave of bank phishing scams around late 2021 and 2022, where victims were lured into entering credentials and one-time passwords on lookalike pages. Local banks have since been shifting toward app-based approval and away from SMS codes and clickable links in texts. That shift tells you how the people responsible for the money see the risk.

Your phone number is easier to take than your phone

A SIM swap needs no hacking of your handset. The attacker contacts your carrier, impersonates you with details gathered from leaks or social media, and asks for your number to be moved to a new SIM. Your phone drops to “no service” and theirs starts receiving your texts, including every reset code. Carriers have added checks, but humans run them, and humans can be fooled or bribed.

If you want to understand how much of your identity leaks from outside your own devices, my piece on what encryption does not hide covers the same theme: the data around the message often matters as much as the message.

Standards bodies have been warning about it for years

This is not just my opinion. The US National Institute of Standards and Technology, in its digital identity guidelines NIST SP 800-63B, classed out-of-band authentication over the public telephone network, which includes SMS, as a “restricted” authenticator. In plain terms, it is allowed but you must accept extra risk and offer alternatives. The US cybersecurity agency CISA says the same thing in its multifactor authentication guidance: any MFA beats none, but SMS and voice codes are the least secure of the common options, and phishing-resistant methods are the target.

The code leaks through your own phone

Notifications preview codes on lock screens. Many people sync messages to a laptop, a tablet or a cloud backup, and a code that lands on all of them is exposed on all of them. Messages can also be read by malware on a handset, by a coworker glancing at your desk, or by someone who borrows your phone for a minute. If you have never thought about which devices mirror your texts, the same logic applies to your browser, which I wrote about in browser sync and who else can see it.

Common misconceptions

“Any 2FA is as good as any other”

No. All second factors are better than none, and that is a real and important gap. But they are not equal. A passkey or hardware security key resists phishing by design, because it only responds to the genuine website address. An authenticator app is not phishing-proof but is immune to SIM swaps. SMS is exposed to both. When I say SMS is weakest, I mean weakest among the second factors, not worse than nothing.

“Nobody would bother attacking me”

Most SIM swap and phishing attacks are not hand-crafted for you. They are scaled. Attackers buy lists of leaked emails and phone numbers, try them against crypto exchanges, email providers and social platforms, and work through the list. You need to be on a list, and with the number of data breaches every year, most of us are. If you ever wonder what happens to your details once a company is sold or breached, see what happens to your data when a company is acquired.

“The code expires, so it is safe”

Expiry stops an attacker reusing an old code. It does nothing against a live phishing page, where the attacker uses your code within seconds, well inside the window.

“If I use SMS I should switch it off right now”

Please do not. If SMS is the only second factor a service offers, keep it on. It still stops the large majority of automated password-stuffing, where criminals try leaked passwords on many sites. The right move is to upgrade where you can, not to go back to a password alone. For accounts that matter, such as your primary email, your bank, your password manager and anything holding money, move to something stronger.

What I actually do

A short, practical order of preference, which is also how I set up my own accounts:

  • passkeys or hardware keys first: a YubiKey or a passkey stored in your phone or password manager. The FIDO Alliance explains how passkeys work and which services support them.
  • authenticator app second: a time-based code app is free and takes about two minutes to set up per account. Print or securely store the backup codes when it asks.
  • SMS last: use it only where nothing else is offered, and tighten the carrier side.

On the carrier side, I ask my mobile provider whether they offer a port-out lock or an extra PIN on account changes, and I keep my phone number out of public profiles where I can. I also use a separate number for sign-ups that never gets used for anything with money attached. People who run many accounts for work, for example managing separate browser profiles, will recognise the same compartment approach that sites like antidetectreview.org cover from the multi-account angle.

Read the privacy terms of any service that asks for your number. Companies often collect it for “security” and then use it for marketing or sharing. I wrote about what those documents really commit a company to in what a privacy policy actually commits a company to.

Where to go from here

If this was your first time looking at 2FA, here is what I would read or do next:

None of this is complicated, and none of it needs paid software. The goal is not perfect security. It is moving your most important accounts one step up the ladder, and leaving SMS for the places where it is the only rung available.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-10-05.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →