ISSUE 33 · 6 MIN READ ·

Your second factor is a text message, and that's the weak link now

If your two-factor codes arrive by text, a SIM swap or phishing proxy can relay them in real time. Why SMS is now the weak link in MFA, and what to switch to.

You did the responsible thing. At some point you turned on two-factor authentication — the extra step where, after your password, a code arrives to prove it’s really you — and a small worry went quiet. The account was covered now. Most people’s second factor is a six-digit code sent by text message, because that’s what the setup screen offered and it worked on the first try.

For years that was solid advice, which is exactly why it’s easy to assume it still is. But the second factor is only as strong as the channel it travels on, and a text message turns out to be a surprisingly leaky one. It can be redirected to an attacker’s phone through a SIM swap — where someone persuades your mobile network to move your number to their SIM — and it can be caught in flight by a phishing page that sits between you and the real login, passing your code straight through the moment you type it. In both cases the code is genuine. It just doesn’t only reach you.

This is the quiet failure: a protection that everyone ticked and then stopped thinking about, which has weakened underneath them while looking exactly the same on screen. It feels like the same lock it always was — and that’s the problem.

Why it stays invisible

Nothing about your login looks different. The code still arrives, the box still turns green, you still get in. From your side there is no sign that the same text could be relayed to someone else, because on a normal day it isn’t. The weakness only shows up on the day someone targets you, and by then the account is already open in two places.

What changed isn’t your phone — it’s the economics on the other side. SIM swapping is now a routine tactic rather than a rare, sophisticated one — the FBI and the US Cybersecurity and Infrastructure Security Agency (CISA) list it among the standard tools of criminal groups such as Scattered Spider — and phishing kits that relay codes in real time are sold ready-made, so an attacker needs no special skill to defeat a texted code. The guidance has moved with the threat, though it has moved carefully. The United States’ standards body, the National Institute of Standards and Technology (NIST), hasn’t banned codes sent over the phone network; its current digital-identity guidance classes them as “restricted”, which means a service may still use them but must offer a stronger alternative, warn users of the risk, and have a plan for moving away. The big providers are heading the same direction — Google has begun replacing texted codes for Gmail sign-ins with QR codes and passkeys. The advice you followed was sound when you followed it; it simply isn’t the strongest option any more.

Find it yourself

This is less a hunt than a five-minute audit of your most important accounts. Take the handful that would hurt most if lost — your email first, since it can reset everything else, then banking, then anything holding customer or company data.

  1. For each account, open its security or sign-in settings and find the two-factor (or “2-step verification”) section.
  2. Look at how the second factor is delivered. If it says a code is texted or phoned to your number, that’s the SMS method — the weak link.
  3. In the same screen, look for the stronger options offered: an authenticator app (a code that generates on your phone without any text arriving), or a passkey or security key (which ties the login to your device and can’t be phished or relayed).
  4. Note which accounts are still on text-message codes. That short list is your to-do list.

Tip: each provider keeps this somewhere slightly different — Google under Security → 2-Step Verification, Microsoft under Security → Advanced security options, Apple under Settings → [your name] → Sign-In & Security — and the labels move from time to time, so if a menu doesn’t match, look for anything named “security” or “sign-in” and work from there.

No authenticator app yet? That’s fine — the audit still works. Simply noticing which accounts rely on a texted code tells you where you’re exposed, and you can add an app before you switch each one over.

The fix

The aim is to keep the second factor but move it off the phone network.

Switch to an authenticator app. For each account still using texted codes, add an authenticator app instead — Google Authenticator, Microsoft Authenticator, or any reputable equivalent. The code is generated on your device rather than sent to your number, so there’s nothing for a SIM swap to steal or a relay to intercept. Once the app is working, turn off the SMS method so it can’t be used as a fallback.

Use a passkey where it’s offered. More and more services now support passkeys or physical security keys, which bind the login to a device you hold and are resistant to phishing by design. Where a critical account offers one, it’s the strongest choice available today.

Protect the number itself. Since some accounts still insist on SMS, ask your mobile network to add a port-out or SIM-change PIN to your account — a small barrier that makes a SIM swap meaningfully harder.

Start with the keystone account. If you do only one thing, do it to the email address that can reset your other logins. Harden that one first, and you’ve protected the account an attacker would target to reach all the rest.

None of this undoes the good you did by turning MFA on — it just moves the same habit onto a sturdier channel. Ten minutes per important account, email first, and the quiet worry can go quiet again for the right reason.

A soft PS: keeping track of which staff accounts still rely on texted codes across a whole team is the sort of thing AuthScope is built to surface — but for your own handful of logins, the audit above is all you need.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.