Article · Updated 18 Jul 2026 · ~9 min read

SMS Verification Is the Weakest Form of 2FA — Here's Why

Awkward angle for a company that sells SMS numbers, but here's the honest version: SMS 2FA has real, well-documented weaknesses. Use it for signup, then move off it. Here are the four attacks and safer alternatives.

The two-second summary

SMS 2FA improves your account security compared to a password alone — but only marginally. It doesn't take a nation-state to break it. Motivated criminals with a phone and some patience defeat SMS 2FA every day. Below are the four attack vectors, ranked by how commonly they're used against ordinary people, plus what to switch to instead.

The short version: hardware key > authenticator app > TOTP > SMS > password alone. Use SMS to sign up for things, then immediately transition to an authenticator app in the settings. Keep SMS as a last-resort backup.

The 4 real attack vectors

1. SIM swap (the big one)

An attacker calls or visits your carrier pretending to be you, claims they lost their phone, and asks for a replacement SIM. If the carrier employee is careless or corruptible, they issue a new SIM tied to your number. From that moment, every SMS to you goes to the attacker's phone, including 2FA codes.

They then reset your bank password (which sends an SMS "reset link"), log in, and drain the account. This isn't rare — it's the standard playbook for stealing crypto wallets and bank accounts. The FBI publishes annual losses in the hundreds of millions of dollars just from SIM swap.

Who's at risk: anyone whose real number is public, on data breach lists, or in a leaked crypto exchange database. Which is most people.

2. SS7 exploits

SS7 is the ancient signalling protocol that carriers use to route SMS between networks. It was designed in the 1970s when only trusted state telecom operators had access. Today, anyone who can rent access to an SS7 gateway — which is technically illegal but practically achievable in some jurisdictions — can intercept SMS in transit or redirect them to a phone they control.

The intercept happens between carriers, so the target's phone and account behave normally. The victim never sees the code arrive. The attacker does. High-value targets (bank executives, senators, journalists) have all been documented as victims. It's less common against random individuals but not zero.

3. Phishing kits with SMS relay

You get a text or email that looks like it's from your bank, click the link, land on a fake login page. You enter your password. The fake page relays the login to the real bank in real time. The real bank sends an SMS 2FA code to you. You dutifully enter it into the fake page (thinking it's the real bank). The relay forwards the code to the real bank, which lets the attacker in.

SMS is uniquely vulnerable to this because the codes are short, human-typable, and echo through the user. Authenticator apps and hardware keys are much harder to phish because there's no code the user manually re-enters for the attacker to steal.

4. Carrier employee bribery / insider fraud

A carrier employee is paid a few hundred euros to run a "swap" or issue a redirect on a target number. Documented cases every year — a US carrier had a whole insider ring taken down in 2020 for this. Small numbers of employees, but the damage per case is high because the attacker gets full control of the number without the SMS-swap paperwork trail.

Nothing an ordinary user can do about it directly. What we can do is not depend on SMS as the sole 2FA factor, so the insider swap doesn't hand over the account.

How SIM swap actually happens (step by step)

Because it's the most common attack, worth understanding in detail:

  1. Attacker collects personal information about the target — full name, date of birth, address, mother's maiden name — from data broker sites, social media, or previous breaches. This is trivially cheap.
  2. Attacker calls the target's carrier, impersonates the target, says the phone was lost/stolen/damaged.
  3. Carrier support asks security questions. Attacker answers using the collected data.
  4. Carrier issues a new SIM (mailed to an address the attacker controls or picked up in store) tied to the target's number.
  5. Attacker activates the new SIM. The target's SIM goes dead — they lose signal.
  6. While target is figuring out what's wrong with their phone, attacker resets bank / crypto / email passwords via SMS 2FA and drains accounts.
  7. Attacker typically has 30–90 minutes before the target realises and can call the carrier to reverse it. By then, the money is gone.

Why authenticator apps are safer

Authenticator apps (Google Authenticator, Authy, 1Password) generate 6-digit codes on your device from a secret shared with the service at setup. The secret never travels over any network after that first setup — codes are computed locally on your phone from the current time.

What that fixes:

The one downside: if you lose the phone that has the authenticator, and haven't backed up the seed, you can lose access. Solution: use Authy or 1Password's cross-device sync, or manually save the backup codes every service gives you at setup.

When SMS 2FA is still OK

Need to sign up but keep your real number private? Buy a virtual number →

How to migrate off SMS 2FA (step by step)

Audit your important accounts and switch them one at a time:

  1. List your high-value accounts. Bank, brokerage, main email, crypto exchanges, cloud storage (Google Drive, iCloud), password manager.
  2. Install an authenticator app. Authy or 1Password give you cross-device sync so a lost phone doesn't lock you out. Google Authenticator now supports cloud sync too.
  3. For each account, go to Security / 2FA settings. Add authenticator-app 2FA. Scan the QR code, verify with a 6-digit code, save the backup codes to your password manager.
  4. Remove SMS as a factor once the authenticator is confirmed working. Some services won't let you remove SMS entirely; leave it as backup if forced, but make sure authenticator is the primary.
  5. Buy a hardware key for the most valuable accounts. YubiKey, Google Titan. €25–50 each. Use them as the primary factor on email and password manager, so even the authenticator seed being compromised doesn't unlock everything.
  6. Add a carrier account PIN. Call your mobile carrier and set an account PIN required for any SIM change. This isn't perfect (insiders can bypass), but it stops the amateur SIM-swap attempts.

FAQ

Is SMS 2FA better than no 2FA?

Yes, meaningfully. Password alone is defeated by any breach or phishing kit. SMS 2FA blocks the majority of remote automated attacks. It's mostly the targeted human attacks (SIM swap, SS7) that beat it. So SMS is a real improvement over nothing — just not the best.

Do I need a hardware key?

For most people, no. Authenticator apps solve 95% of the risk. Hardware keys are worth it for main email, password manager, and any account with serious money. €25 well spent for that.

What if the app I use only supports SMS 2FA?

Unfortunately common with older banks and regional apps. Keep SMS 2FA there but sign up with a fresh virtual number, add a strong unique password, and don't reuse that phone number anywhere else. Reduces the value of an SIM swap since the attacker can't just look up all your accounts by number.

Getting a virtual number to sign up cleanly — start here. Buy a number →