Is SMS Two-Factor Authentication Safe?

The short answer is that SMS 2FA is significantly better than no second factor at all, and worlds better than a password alone, but it's also the weakest form of two-factor authentication still in mainstream use. NIST, the US government body that sets federal digital identity guidelines, formally downgraded SMS as an authentication method years ago, and security researchers have been saying the same thing even longer. None of that means you should panic and rip SMS 2FA out of every account today. It means you should understand exactly what's weak about it, why, and which accounts deserve an upgrade first.
What Happens Behind the Scenes
The mechanics are simple enough to explain in one sentence: the server generates a short-lived code and sends it as a text message to whatever phone number is on file, and entering that code proves you currently have access to that number. The entire security model rests on one assumption, that the phone number reliably and exclusively routes to you. Every major weakness in SMS 2FA is really a weakness in that one assumption, not in the concept of a one-time code itself.
Where SMS 2FA Actually Breaks Down
SIM Swapping: The Attack That Matters Most
SIM swapping is the practical, real-world attack that accounts for the overwhelming majority of SMS 2FA compromises, and it doesn't require touching your phone at all. An attacker convinces your mobile carrier's support staff to move your phone number onto a SIM card the attacker physically controls. From that point forward, every text meant for you, including every 2FA code, arrives on their device instead of yours.
The mechanics of how attackers pull this off are worth understanding in detail, because the process is less technical than people assume and more about social engineering a call center employee. First, the attacker builds a profile on the target using data breaches, social media oversharing, and sometimes purchased data broker records, collecting things like date of birth, home address, and the last four digits of a social security number. Next, they call the carrier's support line, or sometimes walk into a retail store, impersonating the victim and using that collected information to pass identity checks that were designed for a support agent handling hundreds of calls a day, not for catching a well-prepared impersonator. Once the number ports over, they move fast, resetting passwords on email, banking, and crypto accounts within minutes, using SMS codes that now land on their device rather than yours.
This isn't a rare or theoretical scenario. Twitter's own CEO at the time, Jack Dorsey, had his account taken over via SIM swap in 2019. Cryptocurrency holders are targeted specifically and constantly, because crypto transfers are irreversible the moment they're confirmed, unlike a bank wire that can sometimes be clawed back. The FBI has issued repeated public warnings about the scale of SIM swap fraud, and industry estimates put annual losses from crypto-focused SIM swaps alone in the tens of millions of dollars. For an even deeper walkthrough of exactly how these attacks unfold and how carriers are (slowly) responding, see our dedicated guide on SIM swapping attacks explained.
SS7 Interception: The Attack That's Rarer but Real
SS7, short for Signalling System No. 7, is the decades-old protocol telecom networks around the world use to hand calls and texts between carriers. It predates modern security thinking by a huge margin and has well-documented flaws that let an attacker with access to the SS7 network, typically a nation-state actor or an organized criminal group with telecom-level access, intercept SMS messages mid-transit. Critically, this doesn't require touching your phone, your SIM card, or your carrier account at all, it happens at the network layer, invisibly, while your phone behaves completely normally.
Security researchers have publicly demonstrated live SS7 interception, including on television, and documented real-world attacks against bank customers in Germany where SS7 flaws were used to intercept SMS transaction confirmation codes. This attack is far less common than SIM swapping because it requires significant technical resources and network access most attackers simply don't have, but "rare" isn't the same as "never," and it's part of why security agencies won't formally endorse SMS as a strong authentication factor.
Malware Sitting on the Phone Itself
If a phone is already infected, a malicious app with SMS read permissions can silently forward incoming 2FA codes to an attacker in real time, with no visible sign to the phone's owner that anything happened. This risk applies almost entirely to Android devices with apps installed from outside official app stores, or to any device where a user was tricked into granting broad permissions to something that looked legitimate.
Social Engineering the Human, Not the Network
A surprising share of SMS 2FA compromises don't involve any technical attack at all. An attacker calls the victim directly, claiming to be from their bank's fraud department, creates urgency ("we've detected suspicious activity on your account, we need to verify you immediately"), and asks the victim to read back the six-digit code they just received by text. Plenty of otherwise careful people comply, because the caller sounds legitimate and the request feels routine. Authenticator app codes are technically vulnerable to the same trick, but the thirty-second expiry window on TOTP codes makes real-time relay attacks meaningfully harder to pull off than intercepting a text message that can sit in an inbox for minutes.
Recycled Phone Numbers
Carriers reclaim and reassign phone numbers after an account closes, often after a waiting period of just a few months. If you switch numbers and forget that an old account still has your former number attached as its SMS 2FA method, the person who's issued that number next could, in theory, receive a code meant for you. This is a low-probability but genuinely underappreciated risk, and it's a good reason to audit old accounts whenever you change phone numbers rather than assuming they'll simply sit dormant forever.
Why Authenticator Apps Sidestep All of This
TOTP-based authenticator apps eliminate the entire attack surface described above in one move, because they remove the phone network from the equation entirely. Codes are generated on-device using a shared secret established once at setup and the current time, meaning there's no carrier to social-engineer, no SS7 network to intercept, and no SMS message that malware can read. The thirty-second expiry window means even a successfully phished code is close to worthless within seconds. And because generation happens entirely offline, there's no network dependency an attacker can exploit at all.
You can see the mechanics for yourself using our free browser-based TOTP generator, which produces the same time-based codes an authenticator app would, directly in your browser, with nothing sent over SMS or any network at all.
So When Is SMS Still Fine to Use?
Despite everything above, SMS 2FA earns its keep in specific situations, and the nuance matters more than a blanket "never use it" verdict. Google's own research found that SMS-based verification blocks around 96 percent of bulk, automated phishing attempts and roughly 76 percent of more targeted attacks, numbers that make it clear SMS is doing real work against the most common threats most people actually face, even if it's outmatched against a determined, resourced attacker.
SMS is a reasonable choice when it's genuinely the only 2FA option a service offers, since some second factor beats none every time. It's also acceptable on lower-value accounts where the worst-case outcome is mild annoyance rather than financial or reputational damage, a streaming subscription or a hobby forum account doesn't need the same defense posture as your primary email or a brokerage account. Where SMS becomes a real liability is on anything an attacker would specifically target: cryptocurrency exchanges, primary email (since email is usually the recovery path for everything else), banking, and any account tied to your real name and public identity in a way that makes you an appealing SIM swap target in the first place.
Actually Making the Switch to an Authenticator App
Upgrading a single account typically takes under five minutes once you have an app installed. Start by downloading an authenticator, Google Authenticator, Authy, Aegis, and Bitwarden Authenticator are all solid choices depending on your priorities (our full comparison is in Best Authenticator Apps in 2026). Log in to the account you want to upgrade and navigate to its security or two-factor authentication settings. Look specifically for an option labeled "Authenticator App" or "TOTP," which is usually listed alongside the SMS option rather than replacing it outright. Scan the QR code shown, or enter the secret key manually if scanning isn't available, then enter the six-digit code your app generates to confirm the setup succeeded.
Before you close that settings page, save the fresh backup codes the service generates, they're your fallback if you ever lose access to the authenticator app itself, and our guide on storing backup codes safely covers exactly where to keep them. Finally, decide whether to remove SMS entirely as a 2FA method or leave it registered as a secondary fallback. For your most important accounts, remove it outright, an attacker who can choose between two 2FA methods will always pick the weaker one, so leaving SMS active defeats part of the point of adding the stronger method in the first place.
Frequently Asked Questions
If I add an authenticator app, should I turn SMS off completely?
For high-value accounts, yes, remove SMS as an available 2FA method once the authenticator app is confirmed working, since services that offer multiple 2FA options generally let an attacker pick whichever one is weakest. For low-risk accounts where convenience matters more than maximum security, keeping SMS as a backup option is a reasonable compromise.
Is verifying through email actually any safer than SMS?
Not meaningfully, and in some ways it's worse. Email inherits the same fundamental weakness, if the email account itself is compromised, a code sent there provides no real second factor at all. Email verification codes also frequently have longer expiry windows than SMS or TOTP, which widens the window an attacker has to intercept or reuse one.
My bank still only offers SMS. Should I just accept that?
Enable it regardless, since it's still meaningfully better than no second factor. Separately, contact your bank directly and ask them to support TOTP or a hardware security key, banks do track these requests and slowly add options in response to demand. As an interim step, consider registering a secondary number, such as a Google Voice number, specifically for banking SMS that isn't publicly tied to your name anywhere online, making you a less obvious SIM swap target.
Has SIM swapping actually happened to regular people, or mostly celebrities?
Overwhelmingly regular people, the celebrity cases just get more press coverage. The FCC has documented widespread SIM swap fraud affecting everyday account holders, and cryptocurrency holders in particular, who are rarely famous, lose a combined tens of millions of dollars annually to these attacks. It is an active, ongoing, financially motivated crime, not a hypothetical worst case.
Can an attacker intercept an authenticator app code the same way they intercept SMS?
Not through SIM swapping or SS7, since TOTP codes never touch the phone network at all, they're generated locally from a shared secret. The remaining risk is phishing, where a victim is tricked into typing their current code into a fake login page in real time. The thirty-second expiry window makes that attack meaningfully harder to execute than intercepting an SMS message, but it isn't impossible, which is why phishing-resistant methods like hardware security keys sit a level above even authenticator apps for the highest-value accounts.