SMS authentication safety

Is SMS Authentication Still Safe?

If you’ve ever logged into an online account and received a text message with a six-digit code, then you’ve used SMS authentication.

For years, it has been one of the most common ways to protect online accounts. Even today, many banks, retailers, and online services still use it as part of their login process.

It’s true that SMS authentication remains much safer than relying on a password alone, but experts no longer consider this the strongest form of multi-factor authentication available.

As cybercriminals continue to develop new attack methods, many organizations are moving toward more secure alternatives like passkeys and authentication apps.

SMS authentication is just one of many types of multi-factor authentication (commonly known as MFA).

Here’s how it works: Instead of signing in with only your password, you receive a one-time verification code by text message. You enter that code to prove it’s really you trying to access the account.

This extra step makes it much harder for someone to break into your account using only a stolen password. Many account break-ins occur because bad actors take login credentials that have previously been leaked online, and try those same credentials on many different, popular websites. For example, if your Facebook gets hacked, they can try the same email and password combination on Gmail, Shopify, and bank accounts.

SMS can still be hacked, but it’s far better than having no multi-factor authentication at all.

The biggest weakness of texting a one-time code is that SMS messages can be intercepted or stolen. Think about it: How often do you use MFA on the same device where you receive SMS? If the whole device is compromised, then your texts aren’t private or secure.

Here’s another example: Cybercriminals may create fake login pages that trick people into entering both their password and their text message code.

Alternatively, threat actors can use SIM-swapping scams to convince a mobile carrier to transfer a victim’s phone number to a device they control. Once that happens, they can receive the same authentication codes intended for the victim.

While these attacks are relatively uncommon, they happen often enough that cybersecurity experts no longer consider SMS authentication to be the most secure choice for MFA.

Fortunately, there are stronger methods for protecting your most confidential accounts. Consider authentication apps.

What are these? Authentication apps generate verification codes directly on your phone instead of sending them through text messages. Since the codes aren’t transmitted over the mobile network, they’re much harder for criminals to intercept.

Many websites also support passkeys, which allow you to sign in using your fingerprint, face recognition, or your device’s screen lock. Passkeys are designed to resist phishing attacks because they only work with the legitimate website or app they were created for. In fact, approximately 5B active passkeys protect accounts around the world today.

That is one reason companies like Microsoft, Google, and Apple are investing heavily in passkey technology!

Not necessarily.

If SMS authentication is the only multi-factor authentication option available, you should absolutely use it. It provides significantly more protection than relying on a password by itself.

However, if a website gives you the choice between SMS authentication, an authentication app, or a passkey, choosing one of the newer methods will usually provide stronger security.

The goal isn’t to stop using SMS overnight. It’s to use the strongest authentication method available for each account.

No matter which authentication method you use, a few simple habits can help keep your accounts secure:

  • Enable multi-factor authentication on every important account.
  • Use a different password for every website.
  • Never share verification codes with anyone.
  • Be cautious of login pages reached through links in emails or text messages.
  • Switch to an authentication app or passkey whenever one is available.

Together with our common sense and cyber-hygiene habits, we can make it much harder for cybercriminals to gain access to private accounts.

SMS authentication helps protect millions of online accounts and remains much safer than using only a password.

At the same time,you have to remember that cybersecurity is constantly evolving. As criminals find new ways to target text-message verification, stronger authentication methods are becoming the new standard. Who knows what technology will follow?

If you have the opportunity to use an authentication app or a passkey, it’s worth making the switch. Taking a few extra minutes to strengthen your login today can help protect your personal information for years to come!

Related Posts