By NHI Mgmt Group Editorial TeamBased on WorkOS: “Why SMS is not a secure Multi-Factor Authentication (MFA) method” (July 9, 2025)

TL;DR: SMS-based MFA remains widely used, but it is exposed to SIM swapping, phishing, weak carrier identity checks, and code interception across the cellular path, according to WorkOS. For identity teams, the issue is not whether MFA exists but whether the factor is phishing-resistant enough for high-value access.


At a glance

What this is: This is an analysis of why SMS MFA is a weak control for high-assurance identity, with the key finding that carrier-dependent codes are vulnerable to SIM swapping, interception, and phishing.

Why it matters: It matters because IAM teams protecting sensitive applications need to distinguish between having MFA and having phishing-resistant MFA that can withstand modern account takeover paths.


Context

SMS MFA is a high-friction convenience control, not a high-assurance identity control. The problem is not that it adds a second factor on paper, but that the factor depends on carrier processes, number stability, and message delivery paths that security teams do not control end to end.

For IAM programmes, that makes SMS a poor fit for privileged access, regulated workflows, and other accounts where the consequence of takeover is high. The article's core argument is that identity assurance should be measured by resistance to phishing and interception, not by the mere presence of MFA.

The practical question for practitioners is whether their current authentication stack still assumes the mobile network is trustworthy enough for sensitive access. In modern identity programmes, that assumption is increasingly hard to defend.


Key questions

Q: What breaks when SMS MFA is used for high-assurance identity?

A: SMS MFA breaks when the organisation treats a phone number and a delivered code as strong identity proof. SIM swapping, interception, and real-time phishing can all defeat that assumption, especially if credentials are already stolen. For privileged or regulated access, the issue is not second-factor presence but second-factor resistance to takeover paths.

Q: Why do SMS-based MFA flows create more risk than TOTP in custom auth systems?

A: SMS depends on a transport channel that can be intercepted through SIM swap, phishing, or malware, so it is weaker as a primary factor. TOTP reduces exposure by keeping the second factor tied to a shared secret and a local authenticator app, which is easier to govern as a controlled identity artefact.

Q: What signals show that MFA is not actually phishing-resistant?

A: Look for SMS, OTP, push approvals, and broad exception use on high-value accounts. If users can approve login from a fraudulent prompt, if help desk resets re-enable weak factors, or if administrators still rely on shared-secret methods, the programme is not resistant enough to withstand modern phishing.

Q: What happens when organisations keep SMS as a fallback authentication factor?

A: Keeping SMS as a fallback preserves an easy path for attackers after they obtain a password or access to a phone number. It also encourages uneven security, where higher-risk users may still be protected by the weakest factor in the stack. Over time, that undermines zero trust assumptions and leaves critical accounts exposed to bypass attacks.


Technical breakdown

Why SMS OTPs are weak for identity assurance

SMS one-time passcodes are delivered over a channel that is not end-to-end protected and is often mediated by carriers, handset software, and aggregator APIs. That creates multiple interception points. Even when the OTP is generated correctly, the security of the transaction depends on external infrastructure, number ownership, and the user not being socially engineered into revealing the code. In identity terms, the factor is bound to a phone number and a messaging path, not to the authenticated user in a strong cryptographic sense.

Practical implication: treat SMS OTP as a convenience fallback, not a control for sensitive or privileged access.

How SIM swapping breaks SMS MFA

SIM swapping works by persuading a carrier to move a phone number to a new SIM under attacker control. Once the number is reassigned, the attacker receives OTPs and can complete authentication if they already have the username and password. The important failure is not just theft of a message. It is the collapse of the assumption that possession of the phone number proves user presence. That assumption is too weak for high-value identity events and account recovery flows.

Practical implication: remove phone-number ownership as an assurance signal for accounts that can unlock high-impact access.

Why phishing-resistant MFA changes the control model

Phishing-resistant MFA, such as WebAuthn or hardware security keys, binds the authentication ceremony to the origin and to a cryptographic challenge-response flow. That makes it materially harder for an attacker to replay a code from a fake login page. TOTP is better than SMS but still code-based and therefore more exposed to real-time phishing and relay attacks. The control distinction is important: code delivery adds a second step, while phishing resistance changes what the factor can prove.

Practical implication: reserve phishing-resistant authenticators for admin, finance, support, and other high-assurance identity paths.


Threat narrative

Attacker objective: The attacker’s objective is to bypass second-factor controls and take over accounts that the organisation believed were protected by MFA.

  1. Entry begins when the attacker obtains a username and password through phishing or credential stuffing.
  2. Credential access continues through SIM swapping or real-time code interception, allowing the attacker to receive the SMS OTP.
  3. Escalation occurs when the attacker completes login and reaches the protected account or recovery flow.
  4. Impact follows as the attacker gains access to sensitive systems that were supposed to be protected by MFA.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

SMS MFA is an assurance gap, not just a usability compromise: The control answers a delivery problem, not a cryptographic proof problem. That distinction matters because IAM programmes often treat any second factor as equivalent when the real question is whether the factor resists phishing, interception, and recovery abuse. Practitioners should stop measuring MFA by deployment count and start measuring it by the attack paths it actually withstands.

Phone numbers are a brittle identity binding: A mobile number is a routing attribute, not a durable proof of account holder identity. Carrier reassignment, recycling, and support-channel social engineering all break the idea that number possession equals user legitimacy. High-assurance identity programmes should treat phone numbers as contact data, not as a trust anchor.

Phishing-resistant authentication is now the dividing line: WebAuthn and hardware-backed authenticators change the security model by tying the ceremony to origin and cryptographic proof, not shared codes. That is the threshold that matters for privileged users and sensitive business flows. Organisations that keep SMS in critical paths are preserving a known bypass surface.

The governance failure is overloading a low-assurance factor with high-assurance jobs: SMS became the default because it was easy to deploy, not because it was fit for regulated access or recovery. The result is a control that looks like MFA in policy but behaves like a weak step-up in practice. Identity teams should reclassify SMS as a limited-reliability fallback and design policy accordingly.

Named concept: SMS assurance debt: This article exposes the accumulated risk created when organisations keep a familiar factor in place long after its trust assumptions have failed. The longer SMS remains in sensitive access paths, the more programme debt builds across recovery, support, and privileged access. The implication is a phased removal plan, not another layer on top of the same weak factor.

From our research library:

What this signals

SMS assurance debt: The longer teams leave SMS in critical access paths, the more recovery, support, and privileged-access workflows inherit its weak trust assumptions. That debt shows up when organisations need the factor to do work it was never designed to do, such as resisting phishing or carrier-level takeover.

For identity programmes, the signal is clear: MFA strategy has to move from factor count to factor quality. A control that can be replayed, intercepted, or reassigned cannot carry the assurance burden for high-value access, even if it satisfies a checkbox.

Security teams should expect more scrutiny from enterprise buyers and auditors on whether step-up authentication is actually phishing resistant. The governance question is no longer whether MFA exists, but whether the chosen factor can survive the way attackers really operate.


For practitioners

  • Classify SMS as a fallback factor Mark SMS OTP as unsuitable for high-assurance accounts, privileged workflows, and recovery paths where phishing resistance is required.
  • Prioritise WebAuthn for sensitive access Move administrators, finance users, and support staff to hardware-backed or WebAuthn-based authenticators before expanding any remaining SMS use.
  • Audit recovery flows for phone-number trust Review whether account recovery, reset, or step-up paths still treat possession of a phone number as evidence of identity.

Key takeaways

  • SMS MFA looks like a second factor but remains vulnerable to carrier abuse, phishing relays, and message interception.
  • The assurance problem is structural because phone-number ownership is not a durable identity proof for sensitive access.
  • High-assurance programmes should reserve SMS for low-risk fallback use and move critical paths to phishing-resistant authenticators.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationSMS MFA relies on weak authentication assumptions that attackers can bypass through swapping and relay attacks.
NHI-10 — Human Use of NHIPhone-based codes are still human-mediated secrets, which makes them fragile under phishing and social engineering.
Recommendation — Replace SMS-based authentication with phishing-resistant methods for sensitive and privileged access. Reduce human-mediated code handling by shifting critical flows to stronger authenticators.
NIST SP 800-63SP 800-63B — AuthenticationThe article directly discusses high-assurance authentication and NIST's position on SMS.
Recommendation — Use SP 800-63B guidance to phase SMS out of assurance-sensitive authentication paths.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsAuthentication strength determines whether access permissions are actually protected from takeover.
Recommendation — Align authentication strength with access criticality so entitlements are not protected by weak factors.
MITRE ATT&CKTA0006; TA0003 — Credential Access; PersistenceThe article describes credential interception and number takeover as the path into accounts.
Recommendation — Map SMS-based takeover paths to credential access and persistence tactics in your detections.

Key terms

  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • SIM swap: A takeover technique in which an attacker convinces a mobile carrier to move a victim’s phone number to a SIM card the attacker controls. Once successful, the attacker can receive SMS messages and intercept one-time codes, turning the phone number into a compromise path rather than a factor.
  • One-Time Passcode Check: A one-time passcode check is a verification step that proves control of a phone number or other registered channel by requiring a short-lived code. It is a common authentication signal in onboarding and step-up flows. By itself it does not prove identity, but it strengthens confidence that the applicant controls the claimed contact point.
  • High-Assurance Identity: High-assurance identity is an identity that has been verified with strong evidence and can be trusted for sensitive access decisions. It combines rigorous proofing, strong authentication, and ongoing assurance signals such as device, behavior, and context, so the system can rely on the identity with reduced risk of impersonation or fraud.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org