SIM Swap Attack: Why SMS 2FA Is No Longer Enough

Affiliate disclosure: This article contains affiliate links. If you click a link and make a purchase, we may earn a commission at no extra cost to you. Our editorial recommendations are never influenced by commissions — read our full disclosure policy.
The Second Factor Almost Everyone Uses
Type your password, wait for a text, type the six digits. It is the most widely deployed second factor in the world, because it needs no app, no setup and no explanation — everyone already has a phone that receives texts.
It is also the weakest form of 2FA that is still worth having, and the gap between those two facts is where people get hurt. The problem is not that SMS codes are easy to guess. They are not. The problem is that the code is delivered to a phone number, and a phone number is an account held by your mobile carrier, not a possession locked to your handset.
What a SIM Swap Actually Is
A SIM swap does not involve touching your phone. An attacker contacts your mobile carrier, presents themselves as you, and asks for your number to be moved to a SIM they control. Carriers do this legitimately every day — it is how you keep your number when a phone is lost or stolen.
If the request succeeds, your handset silently loses service and every call and text meant for you arrives at the attacker instead. Including the six digits your bank just sent.
The attack is not technical. It is a customer-service attack, and its success depends on how much your carrier's agent can be talked into. What the attacker needs is usually the personal information already sitting in old breach data: name, address, date of birth, the last four digits of something. That is why exposure and account takeover are linked, and why it is worth knowing which breaches contain your details — the free tools for that are covered in checking whether your email was hacked.
What the Standards Body Actually Says
This is where a lot of writing on the subject overstates. NIST Special Publication 800-63B — the US federal digital identity guideline, published June 2017 with updates through 2 March 2020 — does not ban SMS. It says:
"Use of the PSTN for out-of-band verification is RESTRICTED."
Restricted is a defined status, not a prohibition. It comes with an obligation on the service, not on you:
"Verifiers SHOULD consider risk indicators such as device swap, SIM change, number porting, or other abnormal behavior before using the PSTN to deliver an out-of-band authentication secret."
And NIST is explicit that this is a live judgement rather than a settled verdict: it "may adjust the RESTRICTED status of the PSTN over time based on the evolution of the threat landscape and the technical operation of the PSTN."
Read plainly, that is a standards body saying: the delivery channel is outside our control, the failure mode is a SIM change, and services relying on it should be watching for exactly that. It is a warning about the channel, not a claim that SMS 2FA is worthless.
How the Options Compare
| Method | What an attacker must obtain | Beaten by a SIM swap | Beaten by a convincing fake login page |
|---|---|---|---|
| Password only | The password | No | Yes |
| SMS code | Control of your phone number | Yes | Yes |
| Authenticator app code | The secret on your device | No | Yes |
| Push approval | Your tap on a prompt | No | Sometimes, if you approve out of habit |
| Hardware key or passkey | The physical key or device | No | No |
Two things fall out of that table. SMS is the only row that a SIM swap defeats, which is the specific reason it ranks last among real second factors. But every row below "password only" is a genuine improvement on no second factor at all — and the bottom two rows are a different category again, because they are the only ones a fake login page cannot get past. That distinction is the subject of passkeys versus 2FA.
When SMS Is Still the Right Answer
Being honest about this matters more than being purist. Keep SMS when:
- The service offers nothing else. A great many do not, and refusing SMS there means refusing 2FA.
- The account is low value. A newsletter login does not warrant a hardware key.
- The alternative is realistically no second factor at all, because the person using it will not manage an app.
- Your primary email, which every password reset in your life passes through.
- Anything financial. Banking, brokerage, payment apps.
- Cryptocurrency accounts, which are the archetypal SIM-swap target because the transfers are irreversible.
- Your password manager.
- Any account whose recovery flow can be triggered by a phone number.
Hardening the Number Itself
If a service will only do SMS, you can still make the number harder to steal. All of this is done with the carrier, not on the phone:
- Ask for a port-out PIN or a transfer PIN on the account. Most carriers offer one and almost nobody asks.
- Ask for a port-freeze or a number-lock, if available on your plan.
- Ask what identity checks are required for a SIM change, and whether a note can be added requiring in-person verification.
- Remove your mobile number from account-recovery options where it is not needed. A number that cannot trigger a reset is a number worth less to an attacker.
- Treat a sudden, unexplained loss of mobile service as a security event, not a network fault. That is the first symptom.
What to Do This Week
Open your email provider's security settings. If the second factor is SMS, add an authenticator app as an additional method, confirm it works, then remove the phone number as a 2FA method — but only after generating and storing recovery codes, because removing the SMS route without a fallback is how people lock themselves out.
Repeat for your bank and your password manager. Three accounts, perhaps twenty minutes, and the SIM-swap path to the accounts that matter is closed.
Which app to use is covered in best 2FA apps 2026, and the account-by-account setup order is in how to set up two-factor authentication.
The Honest Limits
Moving off SMS closes one attack path. It does not close the others. An authenticator code typed into a convincing fake login page is just as stolen as a texted one, which is why phishing resistance — the property only hardware keys and passkeys have — is the real end state rather than an upgrade from text to app.
And there is a case against the purist position worth stating: a household that abandons SMS 2FA and does not successfully adopt an app has made itself less safe, not more. Better SMS than nothing, every time. The failure mode to avoid is not "used SMS", it is "gave up on 2FA because the alternative was too much trouble".
Covered in this guide
Reviewed by NorwegianSpark Editorial — written with AI assistance and reviewed by the NorwegianSpark SA editorial team · Last updated: 6 September 2026



