FinanceGadget
Guide

Why Your Bank Still Sends Codes by SMS

The short answer

Everyone in security knows SMS one-time codes are weak. Standards bodies have been discouraging them for years, every attack against them is well documented, and banks keep using them anyway.

The reasons are not ignorance. SMS reaches every phone ever made with no enrolment step, works when the customer has no smartphone and no data connection, and — decisively — costs almost nothing to support compared with the alternative. The alternative is not “a better app”. It is a support organisation capable of re-enrolling millions of people who lose devices.

SMS is a rational choice made against constraints that have nothing to do with cryptography. Knowing why it persists tells you what to do about it on your own accounts.

What SMS is actually doing

As a possession factor, SMS asserts that whoever received the code controls the phone number. Not the phone — the number. That distinction is the whole problem.

A phone number is not a cryptographic credential. It is a routing entry in a carrier’s database, changeable by that carrier’s staff, portable between carriers by design, and recoverable through a customer service process built for people who have genuinely lost their phone.

The security of your bank account, when SMS is the second factor, is the security of your mobile operator’s retail identity-verification process. That process was not designed to protect money.

The four attacks

SIM swap. An attacker convinces your carrier to port your number to a SIM they control, usually with personal details assembled from breaches and social media. Every SMS then arrives at their device. SIM swap: protecting your bank accounts covers this in full, including the port-out PIN that mitigates it.

Real-time phishing relay. The attacker runs a proxy that renders the real banking site. You enter credentials on their page; they enter them on the real one. The bank sends you a genuine code; you type it into their page; they replay it within its validity window. The code is real, the session is theirs. This requires no carrier compromise at all and is the most common variant in practice.

SS7 and interconnect interception. The signalling protocols between mobile networks were built when the participants were a small number of state monopolies, and they carry weak authentication between operators. Access to interconnect can allow message interception without touching your carrier account. This is harder and rarer than the other three, but it is real, and crucially it is invisible to you.

Notification leakage. Codes preview on a locked screen by default on most phones. Anyone with physical proximity reads them without unlocking anything. It is the least sophisticated attack on this list and it works in offices, on desks, and in shared homes.

The first two matter most. The relay attack in particular is unaffected by every piece of advice about protecting your SIM, because it never involves your SIM.

Why banks keep it

Universal reach with zero enrolment. Any phone, any network, no app, no setup. For a retail bank with millions of customers spanning every level of technical confidence, this is not a small property. An authenticator app requires a smartphone, an install, an enrolment flow, and a customer who completes it.

Recovery is the real cost. This is the constraint people outside banking consistently underestimate. When a customer loses their phone, an SMS-based bank reissues to the new device and the customer is working within minutes. An app-based bank must re-enrol them, which means re-proving identity — a support call, video verification, or a branch visit. Multiply by the fraction of a large customer base that loses a phone each year and the operational cost is substantial, permanent, and lands on the least technical customers hardest.

Regulation permits it. SCA requires two factors from different categories. SMS qualifies as possession. Regulators have expressed concern about its robustness, but it remains compliant, and compliance is what governs bank roadmaps. Strong Customer Authentication: what PSD2 requires covers the rule.

Legacy backends. Retail banking cores are decades old. Adding a channel that sends a text is a small change. Replacing the authentication model touches everything, in an environment where downtime is a regulatory event.

Fraud losses are budgeted. Banks measure fraud in basis points against transaction volume. If SMS-related fraud costs less than re-enrolling the customer base, the arithmetic favours SMS. This is a cold calculation and it is also, from the institution’s perspective, the correct one.

What actually helps, in order

Use a stronger factor wherever it is offered. Passkeys first, then a hardware security key, then an authenticator app, then push with number matching, then SMS. Most banks now offer at least one better option, frequently without advertising it, and it is usually in security settings rather than anywhere visible. Go and look.

Set a port-out PIN with your mobile operator. This is the single highest-value action for anyone stuck with SMS. It is free, it takes one call, and it converts the SIM-swap attack from a social-engineering problem into one requiring a secret the attacker does not have. Ask specifically for a “port freeze” or “number transfer PIN”.

Turn off message previews on the lock screen. iOS: Settings → Notifications → Show Previews → When Unlocked. Android: Settings → Notifications → sensitive notifications off. Ten seconds, removes an entire attack.

Never type a code into a page you arrived at from a link. This is the defence against relay, and it is the only one available to you. Navigate to the bank yourself, from a bookmark or by typing the address. The relay attack depends entirely on you starting from their link.

Do not use SMS recovery on your email account. Email is the recovery path to everything else, which makes it the highest-value target you own. Put a passkey or hardware key on it and remove the phone number as a recovery method if the provider allows it.

Ask your bank. Customer demand is the input that moves bank roadmaps. It is worth two minutes of a support chat to ask whether app-based or passkey authentication is available and to say you would use it. Individually this achieves nothing; it is nonetheless the only lever a customer actually holds.

The realistic position

SMS is meaningfully better than a password alone, and that is not nothing — it defeats pure credential-stuffing entirely, which remains the highest-volume attack on the internet. The problem is that it is weak against a targeted attacker, and if your accounts are worth targeting, SMS is what stands between them and someone who has decided to try.

The practical stance is to treat SMS as a floor rather than a solution: acceptable where nothing better exists, unacceptable on your email, and always worth replacing on any account holding money the moment the bank offers an alternative.