SMS MFA is an assurance gap, not just a usability compromise: The control answers a delivery problem, not a cryptographic proof problem. That distinction matters because IAM programmes often treat any second factor as equivalent when the real question is whether the factor resists phishing, interception, and recovery abuse. Practitioners should stop measuring MFA by deployment count and start measuring it by the attack paths it actually withstands.
A few things that frame the scale:
- The IBM/Ponemon 2025 Cost of a Data Breach Report found that phishing-initiated breaches cost an average of $4.8M each.
A question worth separating out:
Q: What happens when organisations keep SMS as a fallback authentication factor?
A: Keeping SMS as a fallback preserves an easy path for attackers after they obtain a password or access to a phone number. It also encourages uneven security, where higher-risk users may still be protected by the weakest factor in the stack. Over time, that undermines zero trust assumptions and leaves critical accounts exposed to bypass attacks.
👉 Read our full editorial: SMS MFA is a weak control for high-assurance identity