Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

SIM swapping and MFA bypass: what IAM teams need to fix


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19643
Topic starter  

TL;DR: SIM swapping can redirect SMS-based MFA codes to an attacker, letting groups like Lapsus$ bypass a control many organisations treat as sufficient, according to Unixi. The lesson is that MFA alone does not close account takeover risk when the recovery and phone-number trust chain remains exposed.

NHIMG editorial — based on content published by Unixi: Multi-Factor Authentication (MFA) and the risks of SIM swapping

By the numbers:

Questions worth separating out

Q: What breaks when organisations rely on SMS or email MFA for sensitive access?

A: The control breaks when the second factor can be intercepted, relayed, or socially engineered.

Q: Should organisations prioritise phishing-resistant MFA over other identity projects?

A: For most enterprises, yes, when the goal is to reduce the most common account takeover path.

Q: What do security teams get wrong about SNA and SIM swap fraud?

A: They often assume a binary SNA check is enough to solve the whole fraud problem.

Practitioner guidance

  • Replace SMS MFA on sensitive accounts Move administrators, finance users, support staff, and executives to phishing-resistant methods such as FIDO2 or WebAuthn, and reserve SMS only for low-risk fallback where no better option exists.
  • Lock down number-change and port-out requests Treat mobile number reassignment as a privileged event, require out-of-band verification, and create explicit approvals for SIM replacement or porting requests that affect authenticated users.
  • Review recovery and reset workflows Map every path that can reissue access after a lost device, then harden the steps that rely on help desk staff, carrier support, or email-based resets.

What's in the full article

Unixi's full article covers the operational detail this post intentionally leaves for the source:

  • A plain-English explanation of how SIM swapping works across social engineering, insider collusion, and interception scenarios.
  • Examples of how Lapsus$ used phone-number compromise to bypass MFA at major organisations.
  • The vendor's description of its Universal Single Sign-On approach and how it layers additional credential protection over MFA.
  • A direct comparison between SMS-based authentication and stronger account protection patterns for everyday application access.

👉 Read Unixi's explanation of SIM swapping and MFA bypass risk →

SIM swapping and MFA bypass: what IAM teams need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19234
 

MFA is not a complete identity control when the delivery channel is the weak link. SMS-based MFA assumes that the phone number remains bound to the rightful user, but SIM swapping breaks that assumption before the authentication step even starts. The right security question is no longer whether MFA exists, but whether the second factor can be rerouted by an attacker. Practitioners should treat the channel as part of the identity trust boundary, not outside it.

A few things that frame the scale:

  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected, according to The 2024 ESG Report: Managing Non-Human Identities.
  • In the same research, enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly one exposed identity can become repeated access loss.

A question worth separating out:

Q: Who is accountable when an attacker bypasses MFA through SIM swapping?

A: Accountability usually spans the IAM team, telecom provider, service desk, and application owners because each controls part of the trust chain. NIST SP 800-63 is the right reference for authentication assurance, but operational ownership must also cover recovery workflows and privileged access decisions. The gap is usually governance, not just technology.

👉 Read our full editorial: SIM swapping exposes the limits of MFA-first identity security



   
ReplyQuote
Share: