SMS codes as a second factor: risks and better options
SMS codes beat having no second factor but are the weakest kind. Learn why they can be intercepted or redirected, when they are fine and what to use instead.
Login securityPublished
An SMS code is a second factor delivered as a text message. It is much better than a password alone, and it is easy, which is why so many services still use it. But among the common second factors it is the weakest, because the message travels through the mobile network and is tied to a phone number that can be taken over. The German Federal Office for Information Security (BSI) lists authenticator apps and hardware-based methods as better choices, and warns against receiving the text on the same device you log in with.
This does not mean you must panic. It means you should know where SMS falls short and upgrade the accounts that matter most.
Why SMS is weaker
1. The phone number can be taken over
In a SIM swap, a criminal convinces your mobile provider to move your number to a SIM card they control. From then on, your calls and texts, including login codes, go to them. They need personal data about you and a weak identity check at the provider, not any hacking skill.
2. The network was not built for security
Text messages are not end-to-end encrypted. Signalling systems used between mobile operators have known weaknesses that can, in targeted attacks, allow messages to be redirected. Such attacks require access to operator networks and are rare against everyday users, but the risk exists and is one reason security bodies steer away from SMS.
3. Phishing works just as well
A code you type into a fake website can be passed on to the real one in seconds. SMS offers no protection against that. The same is true of authenticator-app codes. Only phishing-resistant methods stop it.
4. Malware and previews
Malicious apps on a phone can read incoming messages. A code that appears on a locked screen can be read by anyone nearby. If you receive the code on the same phone you use for the login, an infection compromises both factors at once.
5. Practical limits
Messages arrive late or not at all with poor coverage or when roaming. Phone numbers get recycled when a contract ends, and an old number can end up with a stranger who then receives your codes or password-reset messages if you never updated the account.
When SMS is acceptable
- When it is the only second factor on offer. Use it. A weak second factor is better than none.
- For low-risk accounts. The effort to attack you may be higher than the value of the account.
- As a temporary step while you set up something stronger.
Even then, protect the phone number itself: ask your provider for an additional PIN or password for changes to the contract or SIM, and do not use your mobile number as a public contact detail where you can avoid it.
A quick risk ladder
| Situation | Realistic risk with SMS |
|---|---|
| Everyday account, low value | Low. Phishing is the more likely problem |
| Email, cloud storage, social media | Moderate. Takeover can cascade to other accounts |
| Banking, crypto, business accounts | Higher. These are the typical targets of SIM swaps |
| Travelling or roaming | Practical problems, such as delayed or missing codes |
If you travel often, remember that a text code needs mobile coverage and your own SIM. An authenticator app or hardware key works without either, which is a quiet advantage when your phone is abroad or in flight mode.
What banks and security agencies say
Many banks are moving customers from SMS codes to app-based approval, and security agencies have advised for years on methods where the secret does not travel over the mobile network. That does not mean SMS has suddenly become dangerous. It means stronger options exist that take hardly more effort. If your bank or email provider offers an app approval or a passkey, that is usually the better choice.
Better options, in order
- Passkeys. No code to type or intercept, bound to the real site. See passkeys explained.
- Hardware security keys. The strongest widely available second factor, see hardware security keys.
- Authenticator apps. Codes calculated on your device, no phone number needed. Compare options in our authenticator app review and read how TOTP codes work.
- Push approval from a trusted app, with number matching, where offered.
- SMS, where nothing else exists.
How to move away from SMS
- Log in to the account and open its security settings.
- Add a stronger method: authenticator app, passkey or security key.
- Save the backup codes in a safe place.
- Test the new method in a private window.
- Remove SMS as a login method, if the service lets you. Some keep it as a recovery option, so also check the recovery settings and update the phone number or remove it.
Be careful about the last step. Many accounts allow reset by SMS even when a stronger factor is on. An attacker will use the easiest route, so a strong factor next to an SMS reset is only partly protected. Read our page on account recovery for how to tighten this.
The takeaway
SMS codes are a reasonable starting point and a poor finishing point. If you use them today, you have already done the most important thing, which is having a second factor. Upgrade your email, platform and banking accounts first, and take the rest at your own pace.
In short
- SMS is better than nothing, and the weakest common second factor.
- The main weak points are SIM swapping, network weaknesses, malware and phishing.
- Upgrade email, platform and banking accounts first.
- Keep SMS only where there is no alternative, and protect your number with a provider PIN.
Frequently asked questions
Should I turn off SMS codes?
Not if SMS is the only second factor you have. Switch to something stronger where you can, then remove SMS as a login method if the service lets you. Never leave an account with no second factor just because SMS is imperfect.
Can someone really read my text messages?
It is uncommon for ordinary users, but possible through SIM swapping, weaknesses in the telephone signalling network, malware on the phone or a visible lock-screen preview. Targeted attacks are the realistic concern, not mass surveillance.
Why do some banks still use SMS?
SMS reaches almost everybody and needs no app. Many banks are moving customers to app-based or push approval, which is generally stronger. If your bank offers an alternative, take it.
Is a code by email better than SMS?
It depends on your email account. If your mailbox is well protected with its own strong second factor, an email code is not worse, but both are weaker than an authenticator app or a security key.
More in Login security
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.