What if the six-digit code that protects your bank account is, in fact, the most fragile entry point of your entire digital fortune? We have all been conditioned to trust that providential SMS that arrives at the moment of online payment or when logging into our account. It reassures us, it gives the impression that we are well guarded, like a keypad in front of a building. Yet, recent work in cybersecurity has confirmed what some experts have whispered for a long time: this famous code can be intercepted without the attacker ever touching your phone. The weak link isn’t your device, nor even your password. It is the SMS itself, and the aging infrastructure on which it rests. Fasten your seatbelt, we dive into the behind-the-scenes of one of the most formidable scams of our era.
The SMS you thought was secure travels through a flaw that is thirty years old
Imagine the network that routes your SMS could be likened to an old postal system designed at a time when mail carriers all knew each other and no one imagined cheating. This is precisely the case with the SS7 protocol, a technical plumbing dating from the 1980s that links telecom operators around the world. At its birth, trust was the founding principle: every operator was supposed to be an honest actor. The problem is that this old system has never really been hardened against modern intruders.
Result: an attacker who manages to access this infrastructure can intercept and redirect your messages without even touching your SIM card. Your phone stays in your pocket, the screen shows nothing abnormal, and yet the code meant to lock your account flows directly to a stranger. This is the kind of vulnerability that has been demonstrated: an attack capable of capturing authentication codes sent by SMS, the famous 2FA that we believed to be infallible.
SIM swap: how a hacker becomes you with a single call
There is another method, even more sneaky in its simplicity, called SIM swap, or SIM hijacking. The principle? A fraudster convinces your mobile operator to transfer your phone number to a SIM card he controls. No need to physically steal your device: everything happens in the operator’s offices, remotely, by a simple phone call or online.
How does he manage it? By playing chameleons. The hacker first gathers as much information about you as possible: scraps scraped from social networks, data retrieved through phishing campaigns, or information bought on the dark web. Once his dossier is sufficiently fleshed out, he calls the operator posing as you, cites a lost phone or a defective card, and requests a new SIM. As soon as the transfer is complete, all your SMS, including your banking codes, arrive with him. He can then reset your passwords and roam through your accounts as if he were at home.
What banks don’t tell you about the “security code”
The SMS verification has long been presented as the ultimate fix. Yet it suffers from a structural weakness: it depends entirely on the telephone network, and thus on its flaws. The numbers illustrate the scale of the phenomenon. In 2024, the FBI’s online complaint center recorded 982 reports specifically related to SIM swap, for losses exceeding 26 million dollars. A figure down from the peak of 68 million reached in 2021, but which mainly reflects an evolution of methods rather than an lull in activity.
The prime targets? Financial platforms and especially cryptocurrency exchanges, where the sums at stake are dizzying. A fraud network tied to the FTX affair is said to have stolen around 400 million dollars in crypto assets. Organized groups, such as the one nicknamed Scattered Spider, have made a specialty of combining social engineering and SIM swap to circumvent the famous SMS-based 2FA. In other words, the weak link has never been you: it is the channel itself.
Take back control before your number betrays you
The good news is that there are now much stronger defenses. The first recommendation is to abandon the SMS code in favor of an authentication app installed directly on your device, such as those offered by Microsoft, Google, or Authy. Their major advantage: they generate codes locally, without passing through the cellular network. Even if a hacker takes hold of your number, they are left empty-handed.
For the most valuable accounts, the strongest protection remains the hardware key, those small physical devices compatible with the FIDO2 standard, often known as YubiKeys. Resembling a USB key, this object must be physically present to validate a login. It cannot be intercepted remotely, impossible to duplicate with a simple call to the operator. It’s the difference between a keypad that anyone can spy on and a lock that only you hold the key.
Ultimately, this story reminds us of a troubling truth: the security we think we have is sometimes built on foundations several decades old. The SMS was never designed to safeguard our savings, and knowledge is already giving you a head start. So, the next time that little code appears on your screen, will you ask yourself who, really, receives it at the same moment as you?