The MFA Level-Up: Why SMS Codes Are No Longer Enough (and What to Use Instead)

Photo of Brian Largent

Brian Largent

CEO, ArcLight Group

February 25, 2026 7 min read
Share:
Free attack unsecured laptop vector

The MFA Level-Up: Why SMS Codes Are No Longer Enough (and What to Use Instead)

For years, enabling Multi-Factor Authentication (MFA) has been a cornerstone of account and device security. MFA remains essential, but the threat landscape has evolved, and some older methods are no longer pulling their weight.

The most common form of MFA, four- or six-digit codes sent via SMS, is convenient and familiar. It is certainly better than relying on passwords alone. The problem is that SMS is an outdated technology, and cybercriminals have developed reliable ways to bypass it. For organizations handling sensitive data, SMS-based MFA is no longer sufficient. It is time to adopt the next generation of phishing-resistant MFA.

The Three Factors, and Why Passwords Alone Fail

MFA is built on three categories of proof. Something you know, like a password or PIN. Something you have, like a phone, token, or security key. Something you are, like a fingerprint or face scan. Passwords alone are the weakest link because they can be phished, guessed, stolen in bulk from breaches, or cracked with automation. MFA forces an attacker to compromise at least two independent factors, and that is a much higher bar.

Roughly 43% of cyberattacks target small businesses, and most of those attacks exploit weak or stolen credentials. A single compromised password is all it takes to turn a normal Tuesday into a breach notification and a legal headache.

Why SMS-Based MFA Is No Longer Safe Enough

SMS was never designed as a secure authentication channel. Its reliance on cellular networks exposes it to security flaws, particularly in telecommunication protocols such as Signaling System No. 7 (SS7), used for communication between networks.

Attackers know many businesses still use SMS for MFA, which makes those businesses appealing targets. Hackers can exploit SS7 vulnerabilities to intercept text messages without ever touching your phone. Eavesdropping, message redirection, and message injection can all happen inside the carrier network or during over-the-air transmission.

SMS codes are also vulnerable to phishing. If a user enters their username, password, and SMS code on a fake login page, attackers can capture all three in real time and immediately sign in to the legitimate account.

SIM Swapping: A Low-Tech, High-Impact Attack

One of the most dangerous threats to SMS-based security is the SIM swap. A criminal contacts your mobile carrier pretending to be you, claims to have lost their phone, and asks support to port your number to a blank SIM they control.

If they succeed, your phone goes offline and the attacker starts receiving all your calls and texts, including MFA codes for banking and email. Combined with credentials stolen in a phishing attack or bought on a breach dump, they can reset passwords and fully take over accounts.

SIM swapping does not require advanced hacking skills. It exploits social engineering against mobile carrier support staff. Low tech, high impact.

Why Phishing-Resistant MFA Is the New Gold Standard

To shut these attacks down, you have to remove the human element from the authentication handshake. Phishing-resistant MFA relies on cryptographic protocols that tie a login attempt to a specific domain.

The prominent standard is FIDO2, which uses passkeys created with public key cryptography that link a specific device to a specific domain. Even if a user clicks a phishing link, the authenticator will not release the credentials, because the domain on the fake site doesn’t match the legitimate one.

The technology is also passwordless, which removes the target attackers are most used to going after. To win, they now have to compromise the endpoint device itself, which is significantly harder than tricking a person.

Hardware Security Keys

The strongest phishing-resistant option is a hardware security key. These are small physical devices, usually shaped like a USB drive, that plug into a computer or tap against a phone.

To log in, you insert the key or touch a button and it performs a cryptographic handshake with the service. There are no codes to type, and attackers cannot steal the key over the internet. Unless they physically take it from you, they can’t access your account.

Mobile Authenticator Apps and Push Notifications

If hardware keys are not practical across the business, mobile authenticator apps like Microsoft Authenticator or Google Authenticator are a meaningful step up from SMS. These apps generate codes locally on the device, which eliminates the risk of SIM swapping or SMS interception.

Push notifications alone can be abused. Attackers flood a user’s phone with repeated login approval prompts, hoping the user eventually taps “approve” just to stop the noise. This is MFA fatigue. Modern authenticator apps fight it with number matching, which requires the user to enter a number displayed on the login screen into the app. That ensures the person approving the login is physically present at the computer initiating it.

Passkeys: The Future of Authentication

Modern systems are embracing passkeys, digital credentials stored on a device and unlocked with biometrics like Face ID or a fingerprint. Passkeys are phishing-resistant and can sync across an ecosystem such as iCloud Keychain or Google Password Manager. They offer the security of a hardware key with the convenience of a device people already carry.

Passkeys also reduce IT overhead. There are no passwords to store, reset, or manage. Users get a simpler experience and IT gets fewer tickets.

Deploy MFA Everywhere, Not Just on Email and Banking

A common mistake is limiting MFA to the obvious targets. Attackers go straight for the places you haven’t locked down. MFA belongs on:

  • VPN access. Remote work is permanent, and VPNs are a prime target for stolen-credential attacks.
  • Servers and admin consoles. A compromised admin password can expose your entire infrastructure.
  • Remote access tools like LogMeIn, TeamViewer, or ScreenConnect. Popular with support teams and popular with attackers.
  • Cloud applications such as Microsoft 365, Google Workspace, CRMs, ERPs, and EHRs. This is where your real data lives.
  • Any sensitive system. If it matters to your business, a password by itself is not enough.

At ArcLight, we deploy Cisco Duo across our managed clients for exactly this reason. Duo gives us consistent MFA, device trust (so only trusted, up-to-date computers can connect), adaptive access policies that block risky logins automatically, and a user experience that doesn’t generate a flood of help desk tickets.

A Practical Rollout Plan

Implementing MFA is less painful than most owners expect, as long as you sequence it correctly.

1. Assess what you have. Inventory the accounts, applications, and systems that matter most. Prioritize email, cloud services, financial accounts, customer databases, and remote access. Start where the blast radius is biggest.

2. Choose the right solution. Options range from free (Microsoft or Google Authenticator) to business-class platforms like Duo Security, Okta, and Authy. Weigh ease of use, cost, and whether the tool integrates with the software stack you already run.

3. Roll it out in waves. Start with privileged accounts: administrators, executives, finance. Those accounts should never rely on SMS. Then expand to the rest of the team.

4. Train your people. Explain why the change is happening. When users understand SIM swapping, MFA fatigue, and what’s actually at stake, they stop resenting the extra step. Provide clear setup instructions and a named person to call when something goes wrong.

5. Monitor and update. Review MFA settings regularly. Reassess which systems need MFA as your business changes. Have a plan for lost devices, including quick deactivation and backup codes, so a dropped phone doesn’t turn into a lockout crisis.

Common Hurdles and How to Get Past Them

Employee resistance. Some users push back because MFA feels like friction. It is, at first. It becomes muscle memory within a week or two. Show them the real stories of what happens without it.

Integration gaps. Not every legacy application is MFA-ready. Good MFA platforms offer pre-built integrations for popular tools and support custom configurations for the rest.

Cost concerns. Start with free or low-cost options for the long tail of accounts, and invest in a managed platform for the systems that matter most.

Lost or stolen devices. Build a device management policy that covers fast deactivation, remote reset, and backup codes. Cloud-based authenticators that sync across devices reduce pain here.

The Cost of Doing Nothing

Sticking with SMS-only MFA, or worse, no MFA, is a ticking time bomb. It may satisfy a compliance checkbox, but it leaves systems wide open to attacks that are both costly and embarrassing. Upgrading authentication is one of the highest-ROI moves in cybersecurity. The cost of hardware keys, authenticator licenses, or a managed MFA platform is tiny compared to incident response, data recovery, and reputation damage.

If your business is ready to move beyond passwords and text codes, we can help. We specialize in deploying modern identity solutions that keep your data safe without frustrating your team. Reach out and we’ll build an authentication strategy that fits your business.

Photo of Brian Largent
About the Author

Brian Largent

Father to five, husband to one, founder, CEO, and all around swell fella (or so I'm told)

Ready to harden your environment?

Get the 27-point assessment we run on every new client

Two hours. One real engineer. A written report telling you exactly where your gaps are — whether or not you ever hire us.

No hard sell. No obligation. Month-to-month after — cancel anytime.