Active Incident? 24/7 Response →
SleuthX

For Individuals & Families

Is SMS 2FA Safe? Why Text-Message Codes Are the Weakest Link

Any second factor beats a password on its own. But a text-message code is the one a determined attacker can steal without ever touching your phone. Here's the ladder up.

All articles·7 min read·June 29, 2026

The short answer

Two-factor authentication is one of the most effective things you can do to protect an account, and any second factor beats a password alone.

But not all second factors are equal.

A code texted to your phone is the weakest of the common options — worth keeping if it is all an account offers, worth upgrading the moment something stronger is available.

Why a text-message code is the weak link

An SMS code is tied to your phone number, not your phone.

And a phone number can be moved away from you: an attacker who convinces (or bribes) a carrier to port your number, or to move it onto a new SIM, starts receiving your codes without ever holding your device.

That is the SIM-swap attack, and it is the reason a determined attacker treats SMS as a speed bump rather than a wall.

The mechanics of a SIM swap — how the port happens and what to do if your number is hijacked — are their own subject.

If your codes suddenly stopped arriving or your phone lost service unexpectedly, read SIM-swap attack recovery.

This guide answers the broader question: which second factor to choose in the first place.

What NIST actually says

The federal standard worth knowing is NIST's SP 800-63B.

It classifies SMS and voice one-time codes as a “RESTRICTED” authenticator: still permitted, but carrying risk a provider has to weigh and disclose.

Note the exact word — restricted, not banned.

You will sometimes read “NIST banned SMS 2FA”; that is not what the guidelines say.

The honest reading is that SMS is acceptable when nothing better exists, and you should prefer a stronger factor when you can.

The ladder: move up when you can

  1. SMS or voice code — better than a password alone. Keep it as a fallback.
  2. Authenticator app — time-based codes generated on your device, with nothing sent over the phone network to intercept. A large step up from SMS.
  3. Passkey or hardware security key— bound to the real website, so it cannot be phished or replayed. CISA calls this class “phishing-resistant” MFA, and it is the strongest option for the accounts that matter most (email, bank, password manager).

Add the strongest factor each account supports — especially your email, since it is the reset key to everything else.

If an account was already taken over, work the full lock-down in how to secure any account after it has been hacked, and if an attacker keeps getting back in, account compromise recovery can help.

Sources

  1. Cybersecurity & Infrastructure Security Agency (CISA), Implementing Phishing-Resistant MFA (fact sheet). https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  2. Cybersecurity & Infrastructure Security Agency (CISA), Turn On Multifactor Authentication (Secure Our World). https://www.cisa.gov/secure-our-world/turn-mfa
  3. National Institute of Standards and Technology (NIST), SP 800-63B Rev. 4 — Digital Identity Guidelines: Authentication. https://pages.nist.gov/800-63-4/sp800-63b.html
  4. FIDO Alliance, Passkeys — passwordless sign-in. https://fidoalliance.org/passkeys/

Related services

Self-serve forensic tool

Want professional help with hardening your account security?

$995 once — lifetime license

Run the AI forensic agent yourself — every tool unlocked, no subscription.

Meet Your Practitioner

Quinnlan Varcoe

Founder & CEO

GIAC-certified · 9 industry certifications

With operational experience across Fortune 50 security programs and the defense industrial base, Quinnlan founded SleuthX in 2022 to provide clients with the caliber of expertise typically reserved for the largest enterprises. Her work in threat intelligence and digital forensics has earned the trust of 26,000+ cybersecurity professionals who follow her analysis.

“26,000 professionals follow my work because I say what others won't — and I can back it up technically.”

Fortune 50 BackgroundDefense IndustryThreat IntelligenceDigital PrivacyIncident Response
Quinnlan Varcoe, Founder & CEO

SMS 2FA: quick answers

Is SMS 2FA safe to use?
It is far safer than a password alone, so if text codes are the only second factor an account offers, turn them on. But SMS is the weakest form of two-factor: the code travels to your phone number, and a phone number can be stolen through a SIM swap or number port without anyone touching your phone. Where an account offers an authenticator app, a passkey, or a security key, choose that instead.
Did NIST ban SMS for two-factor authentication?
No. NIST classifies SMS and voice one-time codes as a 'RESTRICTED' authenticator in its Digital Identity Guidelines (SP 800-63B) — meaning it can still be used, but with extra risk that providers must weigh and disclose. 'Restricted' is not 'banned.' The practical takeaway is the same: SMS is acceptable when nothing stronger is available, but move to an app or passkey when you can.
What should I use instead of SMS codes?
Step up the ladder: an authenticator app (time-based codes generated on your device) is a big improvement over SMS, and a passkey or a hardware security key is stronger still because it is bound to the real site and cannot be phished or intercepted. Add the strongest option each account supports, and keep SMS only as a fallback where there is no other choice.

Certified Expertise

GIAC

Transparent pricing

Trusted by partners across the practice

DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management
DAS Health
Exhibit A Cyber
Ally Security
KIRO Group
Black Mirage
Kalles Group
Gridware
CQR
Archstone Security
Cyvergence
Sentinel Cyber
Cloud Underground
Seron Security
Hexen
Koru Risk Management