So you finally started using two-factor authentication using text messages and now that is not enough? Sadly, yes. Unfortunately hackers have now started to bypass two-factor authentication via text messages using something called a SIM-swap. A SIM-swap attack is a type of fraud where scammers take control of your phone number by tricking your mobile carrier into transferring it to a new SIM card that they control. Once they have your phone number, they can intercept calls and text messages, including those used for two-factor authentication (2FA), allowing them to gain access to your online accounts
The best way to avoid SIM-swap attacks is by using an autheticator app on your phone like Google Authenticator or a physical token for your second factor. In fact, last year Microsoft rolled out a new policy that won’t even allow SMS text messages as a second factor for Microsoft 365 for new users. Microsoft rolled a set of new policies called Modern Authentication and under the new rules users are required to have two-factor authentication and they can not use SMS. Legacy users still have access to SMS and are allowed to not have 2FA but at some point Microsoft will turn this off altogether and every one will be under Modern Authentication.
While a hacker getting control of your phone number may seem far-fetched, we have seen this happen to clients. It has also happened to Bill Gates, Elon Musk, and Barack Obama. So we are recommending that all businesses move away from SMS 2FA for all accounts that have it. This may include applications, banks, and other websites. If the application or website you use only offers SMS 2FA that is better than nothing. But if they offer app-based 2FA, move to that as soon as possible.
Lastly, after a strong Backup & Disaster Recovery Process, two-factor authentication is the MOST IMPORTANT thing you can do for your security. If you have questions, about two-factor authentication or mutli-factor authentication, please contact us at www.mode5.com.