SMS two-factor authentication: the risks and the safer alternatives
Password & accounts. Updated 2026-09-13. About 5 minutes to read.
Move your email, password manager and bank off text message codes to a passkey, security key or authenticator app, then add a SIM swap lock with your mobile carrier.
A code sent by text message is better than no second step at all. It is also the weakest kind of two-factor authentication, because the code goes to your phone number rather than to your phone, and phone numbers can be moved, intercepted or talked out of you.
The FBI received 1,611 SIM swapping complaints in 2021, with adjusted losses of more than 68 million US dollars, up from 320 complaints over the three years before. This guide explains how text codes get stolen, what the official guidance says and how to move your important accounts to something stronger.
How text message codes get stolen
SIM swap: a criminal convinces or bribes someone at your carrier to move your number to a SIM card they control, then receives your codes. The FBI says this is mostly done through social engineering.
Port-out fraud: your number is transferred to a different carrier in the criminal's name.
Phishing relay: a fake login page asks for your password and then your code, and the criminal enters both on the real site within seconds. Microsoft described exactly this against university staff in 2025.
Lock screen previews: a code that pops up on a locked phone can be read by anyone holding it.
Phone network weaknesses: the signalling systems that route texts between carriers have known flaws that well-resourced attackers can exploit.
Recycled numbers: if you give up a number, its next owner can receive codes for accounts still linked to it.
What the official guidance says
The US National Institute of Standards and Technology lists authentication through the phone network, meaning SMS or voice codes, as a restricted authenticator. Organisations that use it must offer alternatives, and NIST says they should check risk signals such as a recent SIM change or number port before sending a code.
Australia's ACSC advises using passkeys where possible, and otherwise another form of phishing-resistant multi-factor authentication. The UK's NCSC says text messages are not the most secure type of 2-step verification but are far better than none, and it names authenticator apps as the main alternative.
X stopped offering text message two-factor authentication to non-paying users in 2023. Expect more services to phase SMS out.
What to use instead, strongest first
Passkeys: tied to the real website, nothing to type, synced across your devices.
Hardware security keys: tied to the real website and kept on a separate physical device.
Authenticator apps, or push approvals with number matching: cannot be SIM swapped, but a code can still be typed into a fake site.
SMS or voice codes: better than nothing, and acceptable only for low-value accounts or where nothing else is offered.
Move your key accounts off SMS
List the accounts that matter most: main email, password manager, Apple, Google or Microsoft account, bank, mobile carrier account, PayPal and any crypto exchange.
For each one, open the security settings and add a passkey, security key or authenticator app.
Save the recovery codes offline.
Remove your phone number as a two-factor method. Remove it as a recovery option too, but only once you have recovery codes or another backup method set up.
If your bank only offers text codes, check whether its app offers in-app approval, and turn on transaction alerts either way.
Lock your mobile number against SIM swaps
United States: turn on your carrier's protection, such as T-Mobile SIM Protection, Verizon Number Lock or AT&T Wireless Account Lock, and set a port-out PIN. The FCC adopted rules in 2023 requiring carriers to authenticate customers before a SIM change or port-out.
Australia: carriers must use extra identity checks, such as a one-time code, before porting a mobile number. Ask yours to add a PIN or password to your account as well.
United Kingdom: ask your provider to add a password or PIN to your account. Switching providers uses a code sent to your phone by text, so never share a switching code you did not request.
Everywhere: hide message previews on your lock screen. On iPhone open Settings, Notifications, Show Previews and choose When Unlocked. On Android, hide sensitive notification content on the lock screen.
Keep your mobile number off public profiles and people-search sites, since criminals start with a number and a name.
Signs of a SIM swap and what to do in the next 30 minutes
Warning signs include your phone suddenly showing no service or emergency calls only while others nearby have signal, a text about a SIM change or port request you did not make, and password reset emails you did not ask for.
Use Wi-Fi or another phone to call your carrier's fraud line and ask them to reverse the change and lock the account.
Change your email password and sign out of all other sessions.
Call your bank and check for new payees or transfers.
Change passwords on any account that used this number for codes or recovery.
Report it: IdentityTheft.gov or ic3.gov in the US, IDCARE on 1800 595 160 or ReportCyber at cyber.gov.au in Australia, and Report Fraud in the UK at reportfraud.police.uk or 0300 123 2040.
Frequently asked questions
Is SMS two-factor authentication better than nothing?
Yes. It stops attacks that rely only on a stolen or reused password. Use it where nothing else is offered, and upgrade important accounts.
Are voice call codes safer than texts?
No. They go to the same phone number, so a SIM swap or port-out captures them just the same.
Why do banks still use text message codes?
Almost every customer can receive a text, so it is the easiest option to support. Many banks now add in-app approvals. Use the app method if yours offers it.
Should I remove my phone number from my Google or Apple account?
Keep a number only if you need it for recovery and have no better option. Set up passkeys and recovery codes first, then decide. Never remove every recovery method at once.
Can I get my number back after a SIM swap?
Usually, yes. Your carrier can move the number back to your SIM once it confirms your identity. Move fast, because every hour a criminal controls the number is another hour to reset your accounts.