Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› Why do SIM swapping attacks remain so effective…
Authentication, Authorisation & Trust

Why do SIM swapping attacks remain so effective against OTP-based authentication?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Authentication, Authorisation & Trust

SIM swapping works because the phone number becomes the attacker’s delivery channel for one-time passcodes. Once a telco account is socially engineered or weak KYC is bypassed, the attacker receives SMS codes and can complete account takeover even without the password. That makes SMS a weak second factor for high-value systems where number portability and recovery processes are exploitable.

Why SMS OTP is still a soft target

SMS-based OTP remains effective for attackers because it ties authentication to a recoverable telecom account, not just to the user’s device or app. If an attacker can redirect the number through social engineering, SIM replacement, or weak recovery checks, the passcode follows the number. That turns the phone carrier into a critical part of the authentication path.

SMS also has a weaker trust model than phishing-resistant factors. A code sent over a telephone network can be intercepted through number-porting abuse, call forwarding abuse, or compromised recovery processes, so the factor can be satisfied without the legitimate user ever seeing the code. That is why SMS OTP is better than a password alone, but not strong enough for high-value access.

For a broader comparison of MFA methods and the attack patterns that defeat them, see MFA Guide and the external NIST SP 800-63 Digital Identity Guidelines, which both emphasize that authenticator strength matters as much as factor count.

Why SIM swaps bypass the security assumptions behind OTP

A SIM swap is effective because the attacker does not need to defeat the OTP itself. They only need to win the upstream delivery channel, then read the OTP as if they were the subscriber. In practice, that means the telecom recovery workflow becomes part of your authentication boundary, even though it was never designed as a strong identity proofing mechanism.

Once the number is reassigned, the attacker can often combine the SMS code with a stolen password, a reset flow, or a session hijack to complete account takeover. This is especially dangerous when the same phone number is also used for account recovery, help desk verification, or step-up authentication, because one compromised channel can unlock several others.

That is why guidance on workforce identity and recovery should be read together with the phishing-resistant MFA discussion in Workforce Identity Security Guide and the recovery-focused Passwordless and Passkeys Guide. Both are useful because they separate proof of possession from a phone number that can be reassigned.

What actually closes the gap

The practical fix is to reduce dependence on SMS for any account where takeover has meaningful impact. Passkeys, security keys, authenticator-app based OTP, and stronger recovery checks all reduce the chance that a number-porting event becomes an authentication event. The important distinction is not whether a factor is convenient, but whether an attacker can obtain it by manipulating a third party.

Organizations also need to treat recovery as part of authentication design, not as an afterthought. If a help desk, carrier, or self-service reset process can rebind the second factor with weak proofing, then the attacker will target that path instead of the login screen. The control objective is to make the reset path at least as strong as the sign-in path.

For implementation examples and the attack chain behind SMS-based MFA compromise, the most relevant case material is Twilio 0ktapus breach 2022 and CitrixBleed exploitation 2023, which show how attackers often combine OTP weakness with session theft or phishing to finish the takeover.

Risk and Threat Considerations

SMS OTP is attractive to attackers because it creates a single point of failure at the phone-number layer. If the number is ported, forwarded, or reassigned, the attacker can receive live codes, bypassing the intended second factor and often triggering no obvious warning in the target application.

Failure mechanism: The authentication system trusts the telecom delivery path as proof that the legitimate user is present, so control failure at the carrier or recovery process becomes account compromise at the application layer.

Impact: High-value accounts can be taken over with only the password and the ability to redirect SMS, which makes fraud, data theft, and downstream session abuse materially easier at scale.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5, OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesSMS OTP strength and phishing-resistant alternatives are central to this sign-in question.
Recommendation — Prefer phishing-resistant authenticators and stronger recovery for high-value accounts.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe question hinges on OTP authenticator weakness and lifecycle abuse through SIM swaps.
Recommendation — Manage authenticators so SMS cannot serve as the durable second factor for critical access.
OWASP ASVSV6 — AuthenticationThe topic is the weakness of an authentication factor and what stronger sign-in requires.
Recommendation — Require stronger authentication than SMS OTP for sensitive accounts.
CIS Controls v8CIS-5 — Account ManagementSIM swap abuse exploits account recovery and reassignment paths that are part of account control.
Recommendation — Harden recovery and account lifecycle steps so they cannot be used to hijack authentication.

Practitioner Guidance

What to prioritise: Move the highest-risk populations off SMS first, especially admins, finance users, support staff, and any account with recovery authority or downstream privilege. For those users, treat SMS as a legacy fallback, not a primary factor.

What to verify: Check whether number changes, SIM replacement, password resets, and MFA resets can be completed using the same weak proofing steps. If they can, the factor is only as strong as the weakest recovery path.

Practitioner takeaway: SIM swap resistance is won by removing the phone number from the trust decision where it matters most, not by assuming OTP remains safe because it is familiar.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org