04/10/2026
Text messages are not the most secure method for two-factor authentication.
Using SMS relies on telecommunications security, not IT security. Attackers can call a mobile carrier, impersonate a user, and transfer the phone number to a new SIM card.
They then trigger a password reset and intercept the SMS code, bypassing the password entirely.
Transition your accounts to better secured alternatives. Use an Authenticator App or a physical hardware security key.
Have you audited how your employees receive their authentication codes?