Skip to main content
Privacy Tools

Stop Relying on SMS Codes: A Privacy Tool Upgrade That Actually Blocks Phishing

SMS two-factor codes are better than nothing, but they're not phishing-resistant. Here's how to switch to authenticator apps or hardware keys to truly block account takeovers.

You type into Google: “why do I still get hacked even with two-factor authentication?” It’s a fair question. You’ve turned on 2FA, you’re using a password manager, you feel responsible. Yet the news keeps showing breaches. Here’s the blunt truth: if your “2FA” is a texted code, you’re still vulnerable to a whole category of attacks.

This guide is for you if you’ve already ditched password reuse and you’re ready to take the next step. We’re going to walk through exactly how to upgrade your accounts to phishing-resistant MFA — the kind that actually blocks the attacks that SMS-based codes can’t. This is the single most effective privacy tool you haven’t fully deployed yet.

Why SMS Codes Aren’t Enough

Multi-factor authentication (MFA) is great — it requires you to present two different authenticators, like something you know (a password) and something you have (a phone). That stops a stolen password from unlocking your account. Microsoft says enabling MFA can block over 99.9 percent of account compromise attacks (Microsoft Security Blog). But that stat assumes you’re using the right kind of MFA.

SMS-based codes have known weaknesses. CISA documents that attackers bypass traditional MFA through phishing, push bombing (where you get spammed with push notifications until you accept), exploitation of SS7 protocol vulnerabilities, and SIM swapping (CISA Implementing Phishing-Resistant MFA). SIM swapping is a social engineering trick where an attacker convinces your carrier to transfer your phone number to a SIM they control. Once they have your number, they can receive your SMS codes.

So, SMS is a last resort. CISA explicitly says SMS or voice codes should only be used when nothing else is available (CISA Implementing Phishing-Resistant MFA). The gold standard is phishing-resistant MFA: hardware security keys (FIDO2) or passkeys, which are resistant to all four of those bypass methods.

Quick tip: If you can’t get a hardware key right now, switch to an authenticator app (like Google Authenticator or Microsoft Authenticator) that generates one-time passwords, or use push with number matching. That’s better than SMS.

Step 1: Identify Your Most Critical Accounts

Start with the accounts that hurt the most if they’re taken over: email, banking, and cloud storage (CISA Secure Our World). Your email is the master key — it can reset all your other passwords. Your bank is where the money is. Your cloud holds your photos, documents, and maybe your entire life.

For each of these, go into the security settings and look for options like “security key,” “passkey,” “FIDO2,” or “authenticator app.” If you see “SMS” as the only option, that’s a red flag. If you see “hardware key” or “passkey,” that’s what you want.

I know it’s tedious, but you only need to do this once. And the payoff is huge: you’ll be protected against phishing, which Verizon found is a big deal — more than two-thirds (68%) of data breaches involve a non-malicious human element, like someone falling for phishing (Verizon 2024 DBIR).

Step 2: Set Up a Hardware Security Key or Passkey

Hardware keys are small USB or NFC devices that you plug in or tap. They work with your browser and phone, and they’re the most phishing-resistant option available. CISA ranks FIDO/WebAuthn and PKI-based MFA as the gold standard (CISA Implementing Phishing-Resistant MFA).

Here’s the practical walkthrough: buy two keys — one for everyday use, one as a backup. Register both with your critical accounts. When you log in, you’ll be asked to insert the key and touch it. That’s it. Even if a phishing site tricks you into typing your password, the attacker can’t complete the login because they don’t have your physical key.

Passkeys are the newer, software-based equivalent. They’re stored on your device (like your phone or laptop) and use the same FIDO2 standard. You can sync them across devices, but the security model is similar — the private key never leaves your device, and your device must be unlocked to use it.

If you’re not ready to buy hardware, the next best thing is an authenticator app that generates one-time passwords. CISA says that when phishing-resistant MFA isn’t available, app-based one-time passwords or mobile push with number matching are recommended — and SMS should be a last resort (CISA Implementing Phishing-Resistant MFA).

Step 3: Remove SMS as a Fallback

This is the step most people skip. After you set up a hardware key, go back and remove your phone number from the MFA methods. If you leave SMS enabled as a backup, an attacker can still SIM-swap you and bypass your key. CISA warns that SIM swapping is a social engineering tactic where attackers convince carriers to transfer your number to a SIM they control (CISA Implementing Phishing-Resistant MFA).

Also, check if your accounts offer “recovery codes.” Download those and store them somewhere safe — like in your password manager or a safe deposit box. If you lose your hardware key, those recovery codes are your lifeline.

What can go wrong? If you lose your hardware key and haven’t saved recovery codes, you could be locked out of your accounts. That’s a real risk. So, always register two keys or save recovery codes. And don’t forget to update your phone number in your account settings if you change it — otherwise, you might lose access when you need it most.

Step 4: Check Your Breach Exposure

While you’re at it, take a few minutes to check if your email has appeared in a known data breach. Have I Been Pwned is a free service that lets you do this — just enter your email and it shows you which breaches it appeared in (Have I Been Pwned). If your email shows up, change that password immediately. And if you’re reusing passwords anywhere, stop — password reuse enables credential-stuffing attacks (Microsoft Security Blog).

This isn’t just about your email. The FBI’s IC3 received 859,532 complaints in 2024, with reported losses of about $16.6 billion — a 33% increase over 2023 (FBI IC3 2024). You don’t want to be part of that statistic.

Remember, the goal is to make yourself a hard target. Attackers go after easy prey. By using phishing-resistant MFA, you’re no longer easy.

Bottom line

The single best move you can make today is to switch your most important accounts — especially email, banking, and cloud — from SMS codes to a hardware security key or passkey. It takes less than an hour, and it blocks the most common attacks that defeat traditional MFA. Do it now, before you become a statistic.

Sources

  • CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
  • Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
  • Verizon (2024 Data Breach Investigations Report) - https://www.verizon.com/about/news/2024-data-breach-investigations-report-vulnerability-exploitation-boom
  • Have I Been Pwned (About) - https://haveibeenpwned.com/About
  • FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf

Share this article:

Comments (0)

No comments yet. Be the first to comment!