A six-digit code that arrives by text message feels like a solid second lock on a bank or email account, since it seems to require physical possession of a specific phone. In practice, that code travels through decades-old telecom infrastructure and a customer-service process that both have well-documented weak points, and security researchers have spent years demonstrating that a determined attacker does not need to steal a phone to get the code off of it. That gap between appearing secure and actually being secure has drawn sustained attention from banking regulators, telecom security researchers and the federal government’s own standards body.
What Two-Factor Authentication Is Supposed to Add
Standard multi-factor authentication asks for something a person knows, such as a password, plus something a person has, such as a phone that can receive a one-time code. The idea is that stealing a password alone should not be enough to break into an account, because the second factor is tied to a device the attacker does not physically control. Banks, email providers and social platforms have pushed the practice hard over the past decade specifically because leaked passwords are cheap and common on criminal forums, and a second factor is meant to make those stolen credentials useless on their own. That protection works well against a stranger who only has a leaked password, but it depends entirely on the second factor actually being difficult to intercept or redirect.
How the SS7 Signaling Network Enables Interception
Text messages travel over Signaling System 7, a protocol built in the 1970s to let telephone networks route calls and texts between carriers, back when the small number of participants made trust between operators a reasonable assumption. That assumption never scaled to a global network with thousands of interconnected providers, and researchers have repeatedly demonstrated, including live, on-camera intercepts of specific phones using nothing more than access to SS7 gateways available to telecom partners abroad, that someone positioned in the right part of the network can reroute a target’s text messages without the phone owner noticing anything unusual. Carriers have since added monitoring and filtering meant to catch obviously fraudulent SS7 requests, but the protocol itself was never redesigned, so the underlying interception path remains available to anyone who can reach it, whether through a compromised carrier partner, a purchased access broker or a state intelligence service.
SIM Swapping Achieves the Same Result Without Hacking a Network
A more common route bypasses network-level hacking entirely. An attacker who gathers enough personal details from data breaches or social media can call a victim’s carrier, impersonate the account holder, and convince a representative to move the phone number onto a SIM card the attacker controls. Once the swap goes through, every text message meant for the victim, including two-factor codes, arrives on the attacker’s device instead, often before the real account holder even realizes their phone has stopped receiving service. Both routes, network-level interception and a carrier-side swap, land on the same outcome: an attacker positioned to receive whatever a text message was meant to deliver, regardless of whether the victim’s physical phone ever changes hands.
Why NIST Downgraded SMS Codes to a Restricted Authenticator
The federal government’s own security guidance has shifted because of these weaknesses. The National Institute of Standards and Technology’s digital identity guidelines now classify SMS-delivered one-time codes as a “restricted” authenticator, a category that did not previously exist in earlier versions of the standard. Organizations that still rely on text-message codes are directed to document the associated risk, offer an alternative method and monitor for signs of compromise, guidance that amounts to an acknowledgment that SMS should be treated as a fallback rather than a strong second factor. The change matters well beyond federal agencies, since NIST’s guidelines shape security requirements written into banking regulations, cyber-insurance policies and corporate compliance programs across the private sector.
Authenticator Apps and Security Keys Close the Gap
The alternatives NIST points toward do not depend on the phone network at all. Authenticator apps generate codes locally on the device using a shared secret established when the account was set up, so there is no text message to intercept and no carrier account to social-engineer. Hardware security keys go a step further, cryptographically confirming a login attempt without transmitting a reusable code over any network. Passkeys, a newer standard built on the same cryptographic foundation as security keys, extend that same protection to ordinary phones and computers without requiring a separate physical device, and major browser and operating-system makers have built support for them directly into their software. None of these options is immune to every attack, but each removes the specific weakness that makes SMS codes interceptable in the first place: a signal traveling through infrastructure the account holder does not control.
This article was produced with the assistance of AI and reviewed by Morning Overview editors.
More from Morning Overview
- A California supervolcano has bulged upward about two and a half feet since 1978
- The FTC is warning about a scam quietly draining thousands from victims
- The NSA is again telling phone owners to switch off one location setting
- A handful of car transmissions are so tough mechanics say they almost never fail