is two-factor authentication safe can 2FA be hacked is SMS 2FA safe

Is two-factor authentication safe? 5 methods ranked

Adrian Maverick · · 11 min read

Two-factor authentication gets recommended by everyone and explained by almost no one. You are told to turn it on, then told that text codes are broken, then told that authenticator apps can be phished too. All three statements are true. They just describe different attacks, and once you see which method stops which attack, the choice gets simple.

Is two-factor authentication safe?

Yes. Two-factor authentication (2FA) is safe, and an account with any second factor is far harder to break into than one with only a password. The methods are not equal, though. Text and email codes are the weakest, authenticator apps sit in the middle, and passkeys or security keys are the strongest because they cannot be phished.

The evidence for "any second factor helps" is strong. A Microsoft study of its own business accounts, published in May 2023, found that "over 99.99% of MFA-enabled accounts" stayed secure during the investigation period, and that multifactor authentication cut the risk of compromise by 99.22% overall and by 98.56% even when the password had already leaked. The US cybersecurity agency CISA puts it in one line: any form of MFA is better than no MFA.

2FA methods ranked: what each one stops

CISA publishes its own strongest-to-weakest ranking of MFA methods. The table below follows that order and adds the attack most guides leave out, session-cookie theft.

Method Stolen or reused password SIM swap Real-time phishing proxy Push fatigue Session-cookie theft
Passkey or security key (FIDO) Stops it Stops it Stops it Not affected Does not stop it
Authenticator app code (TOTP) Stops it Stops it Does not stop it Not affected Does not stop it
Push prompt with number matching Stops it Stops it Does not stop it Resists it Does not stop it
Push prompt, approve or deny only Stops it Stops it Does not stop it Does not stop it Does not stop it
Email code Stops it, if the inbox has a different password Depends on how the inbox is protected Does not stop it Not affected Does not stop it
SMS or voice code Stops it Does not stop it Does not stop it Not affected Does not stop it

"Not affected" means the attack does not apply to that method. Two things stand out. Every method stops the most common attack, which is someone trying a password that leaked in a breach. And only one row survives a phishing page that relays your code in real time.

Can 2FA be hacked?

Yes, but each bypass works against specific methods. There are four worth knowing.

SIM swapping (SMS and voice codes)

An attacker persuades your mobile carrier to move your number to a SIM they control. Every code texted to you now goes to them. The FBI's Internet Crime Complaint Center counted 971 SIM swap complaints and $17.4 million in reported losses for 2025, down from 2,026 complaints and $72.7 million for 2022 in its earlier reports. Those figures only count victims who filed a complaint under that label, so treat them as a floor.

SMS has a second problem. In guidance written for highly targeted people and last updated in November 2025, CISA says: "Do not use SMS as a second factor for authentication. SMS messages are not encrypted." Anyone with access to a carrier's network can read them.

Real-time phishing proxies (every code you can type)

This is the one that catches careful people. A phishing page sits between you and the real site and passes everything through. You enter your password and your six-digit code, the kit relays both within seconds, and the attacker keeps the logged-in session. Microsoft documented one campaign in July 2022 that "attempted to target more than 10,000 organizations" this way, using off-the-shelf kits such as Evilginx2.

It does not matter whether the code came by text, by email, or from an app. NIST's current standard, SP 800-63B-4, published in July 2025, says authenticators that involve manual entry of a code "SHALL NOT be considered phishing-resistant", because nothing ties the code to the site you are actually on.

Push fatigue (approve or deny prompts)

If your second factor is a phone notification with an Approve button, an attacker who has your password can trigger prompts over and over until you tap yes to make them stop. CISA calls this push bombing. It is how an attacker got into Uber in September 2022. In Uber's own published account of the breach, each login attempt sent a contractor a two-factor approval request, and "eventually, however, the contractor accepted one."

Number matching fixes most of this. Instead of tapping Approve, you type a number shown on the login screen into the app, which you cannot do for a login you did not start.

Session-cookie theft (every method)

After you log in, the site hands your browser a cookie so you stay signed in. Malware on your computer can copy that cookie and replay it elsewhere. As Google's Chrome team wrote in April 2024, this kind of theft "happens after login, so it bypasses two-factor authentication." No second factor prevents it, passkeys included. The defense is keeping malware off the device, logging out of sessions you do not recognize, and not installing cracked software or unknown browser extensions.

Is SMS 2FA safe enough?

It is much better than nothing, and it is the weakest option you can choose. Google's 2019 study with New York University and UC San Diego found that an SMS code sent to a recovery phone number "helped block 100% of automated bots, 96% of bulk phishing attacks, and 76% of targeted attacks." On-device prompts blocked 100%, 99% and 90%. In the same research, "zero users that exclusively use security keys fell victim to targeted phishing."

So a text code stops the bulk attacks most people face. It struggles when someone targets you specifically. NIST classifies phone-network codes as a restricted authenticator, the single one on its list, which means organizations using it must assess and accept the risk and offer an alternative. NIST goes further on email: "Email SHALL NOT be used for out-of-band authentication", partly because the inbox may be protected by nothing more than a password.

If SMS is the only option a service offers, use it. A weak second factor still beats none.

The privacy cost of a phone number

There is a second reason to prefer methods that need no phone number. A number given "for security" has a record of being reused for advertising.

In May 2022 the FTC fined Twitter $150 million after finding that "more than 140 million Twitter users provided their phone numbers or email addresses" for account security, including two-factor authentication, and the company used them to target ads. The FTC's 2019 order against Facebook contains the same lesson. It had to state that Facebook is "prohibited from using telephone numbers obtained to enable a security feature (e.g., two-factor authentication) for advertising."

An authenticator app or a passkey needs no phone number, so there is nothing to repurpose.

Why passkeys and security keys are the safest option

A passkey replaces the typed code with a cryptographic key pair. The private key stays on your phone, computer, or hardware security key. When you sign in, your device proves it holds the key, and you unlock it with a fingerprint, face, or PIN.

Two properties matter:

  • There is no code to steal. Nothing is typed, so nothing can be relayed by a phishing page or read off a text message.
  • The passkey is tied to the real site. Your device will only answer the genuine domain. A lookalike page gets nothing.

That is why CISA calls FIDO authentication "the only widely available phishing-resistant authentication." The FIDO Alliance, which maintains the standard, adds a privacy detail people often ask about: your fingerprint or face scan stays on the device and "is never sent to any remote server."

Adoption is well past the early stage. Google said in May 2024 that passkeys had been used "more than 1 billion times across over 400 million Google Accounts." Microsoft reported "nearly a million passkeys registered every day" in May 2025, and in July 2026 announced that its work-account service, Entra ID, will stop offering Microsoft-provided SMS and voice codes on February 1, 2027.

Check your own accounts in five minutes

An account is only as strong as the weakest sign-in method still enabled on it. Adding a passkey while leaving SMS switched on gives an attacker the easy route. CISA flags this directly: enrolling in a stronger method "does not automatically unenroll the account's SMS."

Run this check on your main email account first, since whoever controls your inbox can reset most of your other accounts.

  1. Open the security settings and find the list of sign-in or two-step methods.
  2. Write down every method listed, including recovery phone numbers and recovery email addresses.
  3. Add the strongest method the service offers: a passkey or security key if available, otherwise an authenticator app.
  4. Save the recovery codes the service gives you, on paper or in a password manager.
  5. Remove SMS and voice as sign-in methods if the service lets you.
  6. Review the list of signed-in devices and sign out of any you do not recognize.

Then repeat for your bank, your password manager, and your mobile carrier account. With the carrier, ask what SIM swap and port-out protection it offers and turn it on.

Your email account deserves the most care on this list. Secria supports two-factor authentication with a standard authenticator app, sign-up asks for no card and no phone number, and account recovery runs on a 12-word recovery phrase you save yourself. The details are in the Secria mail whitepaper, and the full routine for locking down an inbox is in our checklist for keeping your email private.

Is 2FA worth it?

Yes, without qualification. The four bypasses above take effort, skill, or a mistake on your part. A password with no second factor takes none of those. Google's research found that most hijacking attempts come from automated bots using passwords leaked in other companies' breaches, and every method in the table stops that.

The practical order of preference:

  1. Passkey or hardware security key, wherever offered.
  2. Authenticator app code, or a push prompt with number matching.
  3. SMS or email code, when nothing else is available.

Two-factor authentication protects the door. It does not protect what is stored behind it if the provider itself is breached or compelled to hand data over. For email, that part depends on how your mailbox is encrypted, which we compare in our guide to the most private email services.

Frequently asked questions

Can someone get into my account even with 2FA on?

Yes, in specific ways: a SIM swap against text codes, a phishing page that relays your code in real time, repeated push prompts until you approve one, or malware that steals your logged-in session. Passkeys and security keys close the first three. Keeping your device clean handles the fourth.

Is an authenticator app safer than SMS?

Yes. The code is generated on your device, so it never crosses the phone network and a SIM swap cannot capture it. Microsoft's 2023 study found that dedicated authenticator apps outperform SMS. Neither one stops a real-time phishing page, which is why passkeys rank higher.

Are passkeys safer than two-factor authentication?

Passkeys are a form of strong authentication in a single step. The FIDO Alliance describes them as using multiple factors: the device you have, plus the fingerprint, face, or PIN that unlocks it. Unlike codes, they are bound to the real website, so they resist phishing.

What happens if I lose the phone with my authenticator app?

You use the recovery codes the service gave you when you turned 2FA on, or a second method you registered earlier. This is why step 4 of the check above matters. Set up recovery before you need it, and store the codes somewhere other than the phone.

Should I turn off SMS 2FA?

Only after a stronger method is working on that account. Add an authenticator app or passkey first, confirm you can sign in with it, save your recovery codes, and then remove SMS. Never remove your only second factor.

The bottom line

A second factor on your inbox is the highest-value security change most people can make this week. If you want an inbox that pairs it with zero-access encryption on every message in your mailbox, Secria Mail has a free plan.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.