SMS and email checks add a basic layer of confirmation, but they are weak against attackers who can use disposable inboxes, intercepted messages, or accounts built from leaked personal data. When identity data is already compromised, verification codes confirm access to a channel, not the person behind it. That makes them useful as a control, but not sufficient as proof of authenticity.
Why SMS and Email Checks Still Miss Fraudulent Onboarding
SMS and email verification confirm control of a channel, not that the applicant is a genuine person or a low-risk account. That gap matters because fraud often starts with stolen personal data, compromised inboxes, SIM-based interception, or disposable addresses that pass a one-time code test. For onboarding, the key failure is not that verification is absent, but that the assurance level is too low for the decision being made.
Security and identity teams often overestimate a code step because it feels like a hard gate. In practice, an attacker only needs temporary access to the channel, not long-term ownership of the identity, which is why verification can succeed even when the applicant is synthetic, impersonated, or already compromised. See the underlying control challenge in the Anthropic report on AI-orchestrated cyber espionage, which illustrates how adversaries combine automation with weak trust signals.
How Verification Works, and Where the Assurance Breaks Down
SMS and email verification are best understood as possession checks. The workflow is simple: a system sends a one-time code or link to a claimed contact point, and the applicant must respond correctly within a short time window. That confirms channel access at the moment of onboarding, which can still be useful for reducing accidental errors, blocking obvious typos, and adding friction for low-effort abuse.
The problem is that channel possession is not the same as identity proofing. An attacker can pass the step in several recognised ways: by using a mailbox they control, by rerouting or intercepting SMS, by leveraging breached data to answer related checks, or by orchestrating many low-cost registrations until one succeeds. The control also degrades when organisations accept the verification step as a substitute for broader trust decisions, such as whether the applicant is tied to a real-world person, whether the device is already known, or whether the account creation pattern fits expected behaviour.
- Email verification is weakest when inbox creation is cheap and disposable.
- sms verification is weakest when the number can be ported, intercepted, or temporarily controlled.
- Both checks are weaker when identity data has already been exposed in prior breaches.
- Both checks are poor standalone signals for high-value onboarding, regulated services, or fraud-sensitive accounts.
Where this guidance breaks down is when teams treat the code step as an assurance endpoint rather than one signal among several. If the onboarding decision depends on trust, entitlement, or regulatory status, a channel check alone cannot carry the full burden.
When a Code Step Is Useful, and When It Is Only Theatre
Tighter onboarding controls often increase user friction and support overhead, so organisations have to balance conversion against fraud loss and downstream remediation cost. That tradeoff is real, and guidance is not fully consistent across sectors: some teams accept simple verification for low-risk sign-up flows, while others require stronger proofing for financial, healthcare, or regulated access.
The practical distinction is whether the step is being used as a hygiene control or as an identity assurance control. For low-risk accounts, email or SMS can still reduce accidental misuse and basic bot activity. For higher-risk onboarding, it should be treated as a weak factor that needs reinforcement, not as the deciding proof that the applicant is legitimate. The strongest programmes combine it with device history, behavioural signals, document or data validation, and step-up checks when the risk profile changes.
One useful test is whether failure of the code step would change your trust decision, or merely add inconvenience. If the answer is only inconvenience, the control is probably doing its job. If the answer is that the code step is the main barrier to fraud, the organisation has likely placed too much weight on a weak signal.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 — Identities and Credentials Managed | Onboarding hinges on how identity proofing and access are accepted. |
| DE.CM-1 — Monitoring for Unauthorised Activity | Fraudulent onboarding is often exposed through abnormal sign-up patterns. | |
| Recommendation — Require stronger onboarding evidence before granting account access. Monitor onboarding patterns for disposable or high-risk verification behaviour. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | The question is about assurance strength during identity proofing. |
| AAL — Authentication Assurance Level | Channel verification is weaker than durable authentication assurance. | |
| Recommendation — Match verification strength to the identity assurance required. Use higher assurance steps when onboarding trust decisions are material. | ||
| CIS Controls v8 | 5 — Account Management | Fraudulent onboarding exploits weak account creation and verification. |
| Recommendation — Harden account creation gates and review suspicious registrations. | ||
Practitioner Guidance
What to prioritise: Use SMS or email as a confirmation layer, not the primary proofing control, when the onboarding decision has financial, regulatory, or account-takeover consequences. The higher the downstream value of the account, the more the organisation should assume that channel possession may be cheap, temporary, or already compromised.
Decision rule: If the onboarding flow can tolerate a disposable inbox or a temporarily controlled phone number, the verification step is too weak to stand alone. If fraud loss would be material, add stronger evidence of uniqueness, continuity, or real-world linkage before granting full access.
What practitioners underestimate: The main failure is often not code interception itself, but overconfidence in a signal that was never designed to establish personhood or durable trust. Teams usually discover that gap after they have optimised the signup flow for convenience rather than after they have measured assurance quality.
Practitioner takeaway: Treat SMS and email checks as friction, not proof, and reserve proofing decisions for controls that can withstand cheap channel control and synthetic identity abuse.
Related resources from NHI Mgmt Group
- Why do strong IAM controls still leave organisations exposed to audit and fraud risk?
- Why do legally required identity checks still leave mobility platforms exposed to fraud and revenue loss?
- Why do passwords and one-time codes still leave organisations exposed to identity fraud?
- Why does relying on email security alone still leave organisations exposed to phishing risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org