Security

Why text-message codes are the weakest second factor, and what to use instead

A code sent by SMS is better than a password alone, but it can be phished, intercepted or redirected to someone else's SIM. Standards bodies now say to move away from it. Here's the order of preference.

Turning on two-factor authentication with codes sent by text message is one of the best things you can do for an account that only had a password. It's also the weakest kind of second factor there is. Both are true, and the second matters more every year.

Three ways an SMS code fails

It can be phished

A fake login page can ask for your code exactly as it asks for your password, and pass both to the real site within seconds. The US standards body NIST says in its Digital Identity Guidelines that codes you type in by hand "SHALL NOT be considered phishing-resistant", because nothing ties the code to the site you're really on.

It can be redirected

In a SIM swap, a criminal convinces your mobile carrier to move your number to a SIM card they hold, usually with personal details from a breach. From then on, your text messages, including every login code, go to them. US carriers now have to authenticate customers before moving a number and notify them when it happens, under rules the FCC adopted in 2023, but the attack still happens worldwide.

It can be read

Text messages aren't encrypted end to end. The US cybersecurity agency CISA, in its mobile communications guidance from December 2024, puts it plainly: "Do not use SMS as a second factor for authentication."

The order of preference

From strongest to weakest:

  1. Passkeys or hardware security keys. Tied to the real site, so a fake page gets nothing. See our guide to passkeys.
  2. Prompts in an app you're signed in to, where you confirm by matching a number shown on the login screen.
  3. Codes from an authenticator app (Google Authenticator, Microsoft Authenticator, or the one built into your password manager). They can still be phished, but they can't be redirected with your phone number.
  4. Codes by text message. Still far better than nothing.
  5. A password alone.

Switching, step by step

  • Start with your email account, because it can reset every other account, then your Apple or Google account, then banking and shopping.
  • Add the stronger method before removing SMS, and check you can sign in with it.
  • Save the recovery codes each site offers somewhere safe, such as your password manager or on paper.
  • Where a site only offers SMS, keep it on, and ask your carrier about a port-out PIN or "number lock", which makes moving your number much harder.

This address used to carry a 2018 news report about spam texts sent to Facebook users' two-factor numbers. This is a new article on the same subject, written in October 2026.

No comments yet