SMS two-factor authentication: security gap born from an outdated signalling system

Security experts warn that reliance on SMS for two-factor authentication exposes users to sophisticated network vulnerabilities and fraud, prompting a shift towards more secure authentication methods.

Behind every six-digit code sent by a bank sits a communications system built for another era. What looks like a routine security step for online shopping, transfers or account access is still often carried over SMS, even though the channel itself was never designed to protect money or resist modern fraud. Security researchers say that makes text-message authentication far weaker than many users assume.

At the centre of the problem is SS7, the signalling network that links mobile operators around the world. According to security specialists, it rests on a long-standing trust model between carriers and offers little in the way of modern intrusion controls. If an attacker gains access to that signalling layer, messages can be redirected or copied without ever touching the victim’s handset. The CNIL has also warned that SMS-based two-factor authentication can be exposed to interception on the network and to SIM card theft or cloning.

A second and often more practical threat is SIM swap fraud. In these attacks, criminals persuade a mobile provider to transfer a victim’s number to a SIM card they control, usually after gathering personal information through phishing, data leaks or social engineering. Once the number is moved, incoming calls and text messages, including bank codes and password-reset links, go to the attacker instead of the customer. Group-IB and other security firms say this can lead to account takeover, drained bank balances and stolen cryptoassets. The FBI said its Internet Crime Complaint Center recorded 982 SIM swap complaints in 2024, with losses of $25.98 million.

Banks and regulators are pushing customers away from SMS where they can. French government guidance encourages validation inside a banking app, while some lenders, including BNP Paribas, Crédit Mutuel and Banque Populaire, have rolled out digital approval tools that replace text codes for many transactions. Security experts also recommend app-based authenticators, which generate codes locally on a device, or hardware security keys such as FIDO2 tokens, which require physical possession. Users are advised to ask their mobile operator for extra protections on SIM changes and to treat any unexplained loss of signal as a warning sign.

SMS is still better than no second factor at all. But as banks, regulators and researchers make clear, it should no longer be seen as a safe end point for protecting accounts.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.