Over a million two-factor authentication SMS messages intercepted: How to protect yourself

Two-factor authentication (2FA) is meant to safeguard our digital lives, but a recent revelation has exposed a major vulnerability. More than one million SMS-based 2FA codes were intercepted by a shadowy company with ties to surveillance networks. This raises serious concerns about how secure our most common digital security methods really are.

SMS-based 2FA is not secure

While 2FA is a vital tool against account breaches, using text messages to receive authentication codes leaves us exposed. SMS communication is not encrypted, which means that malicious actors can intercept these messages as they move through telecom networks. In this case, a Swiss company named Fink Telecom Services handled the routing of around 1 million SMS codes during June 2023, including messages from Google, Meta, Amazon, and several European banks.

Governments and hackers could bypass your security

The intercepted messages included verification codes for services like Signal, WhatsApp, Binance, Tinder, and Snapchat, targeting users in over 100 countries. With access to both a username and password, an attacker could bypass 2FA protection by using these compromised codes. Despite Fink’s claim that it only offers routing infrastructure, cyber experts suggest the company has been linked to earlier incidents of code interception.

Use more secure alternatives

To stay safe, we should avoid using SMS for 2FA whenever possible. Authenticator apps like Google Authenticator or Authy offer stronger protection, as their codes are stored and generated locally. Better yet, using passkeys with Face ID or Touch ID adds an additional layer of security, completely removing the need to send codes across networks.