Privacy & Security · 14 min read

    Why SMS IsNo Longer Secure

    SMS was designed in 1985 — years before the internet existed as we know it. Billions of people still rely on it daily for messages and authentication codes. This is a detailed account of why that trust is misplaced, and what the alternatives are.

    SS7 Vulnerabilities
    SIM Swapping
    Carrier Interception
    Metadata Risks
    Secure Alternatives

    SMS Was Never Designed to Be Secure

    The Short Message Service — SMS — was first defined in 1985 as a side channel for the GSM mobile standard. Its original purpose was operational: a low-bandwidth way for network engineers to communicate system status alerts across carrier infrastructure. The idea that ordinary people would one day send billions of personal messages, financial confirmations, and two-factor authentication codes over this channel would have seemed absurd to its designers.

    That origin story explains everything that is wrong with SMS security today. The protocol was never designed to be encrypted. It was never designed to authenticate senders. It was never designed to protect content from the carrier network. It was designed to be cheap, reliable, and backwards-compatible — and on those terms, it has been extraordinarily successful. On every security metric, it has failed.

    When you send an SMS message, the text travels from your phone to your carrier's nearest cell tower as an unencrypted signal. The carrier's infrastructure reads the message, routes it through the carrier's internal switching systems, and delivers it to the recipient's carrier. At every hop in that journey, the message exists in plaintext. The carrier can read it. A rogue employee can read it. A court order can compel the carrier to produce it. An attacker who can access the carrier's signalling network can intercept it in transit.

    This is not a hidden vulnerability that was recently discovered. Security researchers have known for decades that SMS is fundamentally insecure. Carriers have known. Regulators have known. Governments have known — and in many cases, actively exploited these weaknesses rather than pushing for their repair. The continued widespread use of SMS for sensitive communication and security verification is one of the largest systemic security failures of the digital age.

    To understand why SMS is not secure, it helps to examine each layer of vulnerability separately. They are compounding: a well-funded attacker does not need to exploit all of them. Any single one may be sufficient to compromise a target's communications entirely.

    Key Fact

    SMS messages are transmitted and stored in plaintext on carrier infrastructure. There is no end-to-end encryption in the SMS standard. The carrier — and anyone with legal, technical, or social-engineering access to the carrier — can read every message you send.

    SS7: The Protocol Flaw Behind Every Carrier

    Underneath the modern mobile network lies a piece of infrastructure called SS7 — Signalling System No. 7. Developed in 1975, SS7 is the protocol that allows telecom carriers around the world to coordinate with each other: routing calls across networks, enabling roaming, managing billing, and delivering SMS messages between carriers. Nearly every phone call and text message on the planet touches SS7 at some point.

    SS7 was designed for a world where only a small number of trusted national telephone operators had access to the signalling network. In that world, security through exclusivity made sense: if only AT&T, BT, and Deutsche Telekom could send SS7 messages, there was no need to cryptographically authenticate them. Trust was assumed from network membership.

    That trust model collapsed with the liberalisation and globalisation of telecommunications. Today there are thousands of telecoms operators and virtual operators worldwide, and SS7 access can be obtained through carrier partnerships, SS7 gateway services sold on dark web markets, or simply by registering a small mobile virtual network operator (MVNO) in a jurisdiction with lax oversight. Once an attacker has SS7 access, they can send forged SS7 messages to any carrier in the world — and the network will obediently act on them.

    What an SS7 Attacker Can Do

    The capabilities available to an SS7 attacker are alarming in their breadth. The most directly relevant to SMS security are:

    Intercept SMS Messages

    By sending a forged SS7 "register subscriber" command, an attacker can instruct the global network to route a target's incoming SMS messages to an address the attacker controls. The victim's phone continues to appear operational; they simply never receive certain messages.

    Real-Time Location Tracking

    SS7 contains commands designed for legitimate network management that reveal the approximate location of any phone on the network — down to the cell tower level. This capability has been commercially sold as "location intelligence" and exploited by stalkers, private investigators, and foreign governments.

    Call Interception and Redirection

    Calls can be forwarded to an attacker-controlled number before being connected to the intended recipient. This enables man-in-the-middle eavesdropping on phone calls in real time, with neither party aware.

    Denial of Service

    SS7 commands can be used to temporarily remove a phone from the network entirely — silencing a target, preventing them from receiving calls or texts, or blocking emergency communications at a critical moment.

    Documented SS7 Attacks in the Real World

    SS7 vulnerabilities are not theoretical. In 2017, German researchers from the Security Research Labs demonstrated live on television how they could intercept an SMS message sent to a phone number belonging to US Congressman Ted Lieu — with his permission, as a demonstration. The researchers needed only Lieu's phone number and access to an SS7 network. The intercept took minutes to set up.

    In 2019, the US Senate Intelligence Committee heard testimony that foreign adversaries were actively exploiting SS7 to target American citizens and government officials. In 2021, the telecommunications regulator Ofcom in the United Kingdom published an audit confirming that SS7 attacks against UK networks were ongoing. Cryptocurrency exchanges have confirmed that SS7 attacks were used to intercept SMS 2FA codes and drain customer accounts.

    The fundamental problem with SS7 is structural: the protocol cannot be patched. Replacing it would require the simultaneous cooperation of every telecom operator on earth. The industry has developed mitigation frameworks (GSMA's FS.11, for example), but adoption is uneven, compliance is not enforced, and the mitigations address symptoms rather than the underlying architectural problem. SS7 will remain a vulnerability for as long as it remains in use — and it remains in use everywhere.

    SIM Swapping: Social Engineering Your Phone Number

    While SS7 attacks require technical infrastructure, SIM swapping — also called SIM hijacking or port-out fraud — requires almost none. It exploits not a protocol flaw but a human one: the willingness of carrier customer support staff to help customers who have "lost" their phones.

    In a SIM swap attack, a fraudster calls (or visits) the target's mobile carrier and impersonates the account holder. Using personal information gathered from data breaches, social media, or phishing attacks, they convince the support agent to transfer the target's phone number to a new SIM card — one that the attacker controls. Once the port is complete, all calls and SMS messages intended for the victim go to the attacker's device. The victim's phone, meanwhile, loses service and displays "No Service" or "SOS Only."

    How Attackers Obtain the Information They Need

    The information required to impersonate an account holder at a carrier — name, address, date of birth, last four digits of a Social Security number (in the US), account PIN — is alarmingly easy to obtain. Much of it has already been exposed in data breaches affecting credit bureaux, healthcare providers, financial institutions, and retailers. The 2017 Equifax breach alone exposed the names, Social Security numbers, birth dates, and addresses of 147 million Americans.

    Attackers also conduct targeted reconnaissance through social media (birthday posts reveal birth dates; location check-ins reveal addresses), phishing emails that harvest account credentials, and "pretexting" calls where they warm up a target's account to gather additional details before the swap itself. In some cases, attacks have been conducted with the inside assistance of carrier employees who were bribed or coerced.

    The Consequences of a SIM Swap

    The consequences of a successful SIM swap range from severe to catastrophic. Once an attacker has control of a victim's phone number, they can:

    • Receive all SMS two-factor authentication codes sent to the number, enabling takeover of email, banking, social media, and cryptocurrency accounts.
    • Reset account passwords by receiving the verification link via SMS, bypassing additional security questions.
    • Access and drain cryptocurrency wallets — many exchanges use SMS 2FA for transaction confirmation.
    • Lock the victim out of their own accounts by changing passwords and recovery emails after gaining access.
    • Impersonate the victim to their contacts using messaging apps linked to the phone number.

    High-profile SIM swap victims include Twitter CEO Jack Dorsey (whose account was hijacked in 2019), multiple US senators and members of Congress, and numerous cryptocurrency investors who collectively lost hundreds of millions of dollars. A 2022 FBI alert confirmed that the agency had received over 1,600 SIM swap complaints in 2021, with losses exceeding $68 million — and that figure represents only reported cases in one country.

    Carriers have implemented some countermeasures: account PINs, number transfer bans, biometric verification requirements. But these protections are inconsistently enforced, can often be bypassed by a sufficiently persistent attacker, and do nothing to address the underlying problem: that a phone number is not a secure identity anchor, and that SMS codes sent to it are not a secure authentication factor.

    Carrier Interception and Legal Backdoors

    Beyond external attackers, the architecture of SMS means that your carrier — by necessity — has full access to every message you send and receive. This is not a design flaw in the commercial sense; it is an intentional feature of how carrier-mediated communication works. The carrier is the intermediary that delivers your messages. To deliver them, it must read them.

    Carriers in the United States and most other developed countries are legally required to maintain lawful intercept capabilities — the technical ability to provide real-time access to communications when presented with a court order. In the United States, this requirement is codified in the Communications Assistance for Law Enforcement Act (CALEA), passed in 1994. CALEA mandates that telecommunications carriers build surveillance capabilities directly into their network infrastructure, ensuring that law enforcement can access communications upon receipt of the appropriate legal authorisation.

    This means that every major US carrier — Verizon, AT&T, T-Mobile — operates purpose-built surveillance infrastructure that can intercept your SMS messages in real time. The same is true of carriers in the UK (under RIPA and the Investigatory Powers Act), Canada, Australia, and the European Union. These interception systems are subject to legal oversight in democracies with strong rule of law — but legal oversight is not perfect, and the systems themselves can be exploited.

    The AT&T Room 641A Case

    In 2006, AT&T whistleblower Mark Klein revealed the existence of "Room 641A" at AT&T's San Francisco switching facility — a secret room where AT&T had installed equipment that gave the NSA access to AT&T's entire internet traffic stream, including email and SMS metadata. Similar facilities were alleged to exist at other major carriers. The programme was part of the NSA's warrantless wiretapping infrastructure revealed in greater detail by Edward Snowden in 2013.

    Snowden's disclosures confirmed that the NSA operated programmes — including PRISM, XKeyscore, and the bulk telephony metadata collection programme under Section 215 of the USA PATRIOT Act — that harvested communications data at scale from US carriers. While Section 215 bulk collection of phone records was ended in 2015 following the USA FREEDOM Act, the underlying infrastructure and capabilities largely remain in place.

    IMSI Catchers: Fake Cell Towers

    Beyond carrier-level interception, law enforcement agencies at the local, state, federal, and foreign level operate IMSI catchers — devices that impersonate legitimate cell towers to intercept mobile communications. Commercially sold under trade names like StingRay, Hailstorm, and KingFish, IMSI catchers work by broadcasting a stronger signal than nearby genuine towers, causing nearby phones to connect to them.

    Once a phone is connected to an IMSI catcher, the device can intercept SMS messages, track precise location, identify the IMSI (unique phone identifier) of all devices in range, and in some configurations, downgrade connections from 4G/5G to older protocols that are easier to intercept. The use of IMSI catchers by US law enforcement agencies has been documented in cities including Chicago, Los Angeles, Baltimore, and New York. Their use has frequently occurred without judicial oversight, and several court cases have found their warrantless deployment unconstitutional.

    The existence of IMSI catchers used by adversarial foreign intelligence services in Washington DC was confirmed in a 2017 DHS report. The report found dozens of apparent IMSI catcher deployments near the White House, Capitol Hill, and federal agencies — attributable to foreign embassies using them to harvest communications from US government officials.

    Metadata: What Carriers Know Without Reading a Word

    Even if an SMS message's content is somehow protected, the metadata surrounding it represents a rich and largely unprotected stream of personal information. Metadata is data about data: not what you said, but who you said it to, when, how often, from where, and for how long. For SMS, the metadata your carrier collects includes:

    Sender & Recipient Numbers

    Every phone number involved in the exchange.

    Timestamp

    Exact time of send and delivery, down to the second.

    Cell Tower Location

    Which tower handled the message, pinpointing your location.

    Message Volume

    How many messages were exchanged and at what intervals.

    Device Identifiers

    IMSI, IMEI, and other device-level identifiers.

    Roaming Data

    Which networks were visited when travelling internationally.

    This metadata is stored by carriers for varying periods — months to years in most jurisdictions, and indefinitely in others. It is subject to subpoena in civil litigation, accessible to law enforcement under a much lower legal threshold than content (often requiring only a court order rather than a warrant), and commercially sold to third-party data brokers in some jurisdictions.

    A 2018 New York Times investigation revealed that carriers including AT&T, Sprint, and T-Mobile were selling customers' real-time location data — derived from the cell tower metadata described above — to a supply chain of data brokers, who in turn sold it to bail bond companies, bounty hunters, and private investigators. The carriers were notified, promised to stop, and in many cases continued. The FCC ultimately fined the carriers a combined $200 million in 2024, though the fines were immediately challenged in court.

    The metadata picture painted by SMS records is far more revealing than most people realise. The time pattern of your messages to an oncologist reveals a medical situation you have not shared publicly. The frequency of contact between two people reveals the nature of their relationship. The pattern of late-night messages to an unfamiliar number tells a story. The combination of cell tower data and timestamp data creates a near-complete record of your physical movements through the world.

    Former NSA Director Michael Hayden was not speaking abstractly when he said "We kill people based on metadata." The US drone programme's targeting decisions relied heavily on metadata analysis — call patterns, location data, contact networks — to identify and track individuals. The same analytical techniques are available to any sophisticated organisation with access to telecom metadata.

    Government Access Around the World

    Government access to SMS data is not limited to emergency situations or terrorism investigations. In most countries, the legal frameworks governing access to telecommunications data are broad, the oversight mechanisms are weak, and the volume of requests made to carriers is enormous.

    United States

    In the United States, law enforcement access to SMS content requires a warrant supported by probable cause — a constitutional protection under the Fourth Amendment, as clarified by the Supreme Court in Carpenter v. United States (2018). However, access to metadata requires only a court order under the Stored Communications Act (SCA), a lower legal threshold. National security agencies can obtain SMS content and metadata through FISA (Foreign Intelligence Surveillance Act) orders, National Security Letters (which do not require judicial approval), and emergency authority provisions.

    In 2023, the major US carriers collectively received over 900,000 law enforcement data requests. The vast majority were for metadata rather than content, but carriers also comply with content requests regularly. There is no public reporting requirement for the volume of National Security Letters issued, which cover a potentially large additional tranche of government-compelled access.

    United Kingdom

    The UK's Investigatory Powers Act 2016 (colloquially called the "Snoopers' Charter") is one of the most expansive surveillance laws in any democracy. It requires telecommunications providers to retain communications data — including SMS metadata — for 12 months. It grants intelligence agencies (GCHQ, MI5, MI6) the power to conduct bulk interception of communications, including SMS content, with minimal individual judicial oversight. It also allows equipment interference (hacking into devices) as an intelligence tool, authorised by warrant.

    The UK government has additionally sought, through legal and political pressure, to require messaging platform providers to build backdoors into end-to-end encrypted communications — a campaign that directly illustrates the government's view that encrypted communication is a threat to state surveillance capabilities.

    Authoritarian Regimes

    In countries without independent judiciaries or meaningful legal protections, government access to SMS data is effectively unlimited. China's national intelligence law obligates all Chinese companies and individuals — including telecommunications carriers — to cooperate with state intelligence operations without any procedural constraint. Russia's SORM (System for Operative Investigative Activities) requires carriers to install FSB-controlled hardware at switching stations, giving the security services direct access to all communications without any carrier mediation or judicial oversight.

    For activists, journalists, opposition politicians, and human rights workers in these environments, SMS is not just insecure — it is actively dangerous. Documented cases of imprisonment, torture, and execution have followed the interception of SMS messages in China, Iran, Ethiopia, Saudi Arabia, and elsewhere. The Human Rights Watch and Amnesty International regularly document cases where telecommunications surveillance of SMS has contributed to human rights abuses.

    Cross-Border Government Access

    National borders provide limited protection against government surveillance of SMS. Intelligence-sharing alliances — most notably the Five Eyes (US, UK, Canada, Australia, New Zealand) and the broader 9-Eyes and 14-Eyes partnerships — mean that surveillance data collected by one member nation can be shared with others, allowing nations to circumvent their own legal restrictions by requesting that an allied agency collect the data. The UKUSA Agreement governing Five Eyes intelligence sharing is not subject to domestic judicial oversight in any member country.

    Why SMS Two-Factor Authentication Fails

    One of the most damaging consequences of SMS's continued use is its adoption as a second authentication factor for online accounts. The logic was sound at the time: a code sent to your phone adds a layer of security beyond a password alone. If an attacker steals your password, they still cannot log in without physical access to your phone. For low-sophistication attacks, this defence holds.

    For any attacker with moderate resources or technical capability, SMS 2FA provides only the illusion of security. Every vulnerability described in this article applies directly to SMS authentication codes:

    • 📡 SS7 interception

      An attacker with SS7 access can redirect your incoming SMS messages to their own device before a 2FA code expires — typically a 30-60 second window, more than sufficient.

    • 📲 SIM swapping

      Once an attacker has swapped your SIM, all 2FA codes go to them. They can drain your accounts in the window between the swap and your discovery that your phone has lost service.

    • 🦠 Device malware

      Android malware can intercept and forward SMS messages in the background. Several malware families specifically target banking SMS codes for account takeover.

    • 🎭 Real-time phishing

      Attackers create fake login pages that proxy credentials and 2FA codes to the real site in real time, completing the login before the code expires.

    NIST — the US government's National Institute of Standards and Technology — issued guidance in 2016 (NIST SP 800-63B) recommending that agencies "deprecate" SMS OTP (one-time password) as an authentication mechanism, citing SS7 vulnerabilities and SIM swapping. The guidance has been updated and maintained through subsequent revisions.

    Despite this, SMS 2FA remains the default second factor at the majority of banks, social media platforms, email providers, and online retailers. The gap between what security experts recommend and what organisations deploy persists because SMS 2FA is cheap to implement, requires no app installation by the user, and works on every phone — including feature phones without internet access. Convenience has consistently defeated security in the design of authentication systems.

    If you are currently using SMS 2FA on high-value accounts — email, banking, cryptocurrency, primary social media — you should switch to an authenticator app (Google Authenticator, Authy, 1Password) or a hardware security key (YubiKey, Google Titan) as soon as the service supports it. The migration takes minutes. The risk reduction is substantial.

    Modern Secure Alternatives to SMS

    The good news is that the insecurity of SMS does not require you to accept insecure communication. A generation of encrypted messaging applications and authentication tools has emerged that renders SMS obsolete for security-conscious users. The transition requires changing habits, but it requires no technical expertise.

    End-to-End Encrypted Messaging Apps

    Signal

    The open-source gold standard. Signal Protocol uses X3DH for key exchange and the Double Ratchet Algorithm for forward secrecy on every message. It encrypts not only messages but voice calls, video calls, group chats, and file transfers. Signal requires a phone number to register — a meaningful privacy tradeoff — but collects minimal metadata and stores none of your message content on its servers. Safety number verification lets you confirm you are talking to the correct person. For most users transitioning from SMS, Signal is the right first step.

    Zitto

    Zitto implements the same Signal Protocol cryptographic foundation — X3DH and Double Ratchet — but goes further on anonymity and metadata protection. Registration requires no phone number or email address; accounts are identified by a randomly generated ID. Ghost mode hides your online presence entirely. The dead man's switch feature allows automatic message and account deletion if you do not check in. For users who need not only encrypted content but anonymous identity, Zitto is built around the principle that the server should know as little as possible about who you are and who you talk to.

    WhatsApp

    WhatsApp has used Signal Protocol for end-to-end encryption since 2016, making it significantly more secure than SMS for message content. Its 2 billion user base means that the people you want to communicate with are already there. However, WhatsApp's integration with Meta means extensive metadata collection — who you talk to, when, how often, your device, your IP address. If your threat model includes advertising surveillance or data aggregation, WhatsApp is not a complete solution, though it remains far superior to SMS.

    Secure Alternatives for Two-Factor Authentication

    Replacing SMS 2FA is arguably more important than replacing SMS messaging, because 2FA codes protect your most critical accounts. The recommended alternatives in order of security strength are:

    #1

    Hardware Security Keys

    FIDO2/WebAuthn hardware keys (YubiKey, Google Titan, Apple Passkey) are the most phishing-resistant 2FA method available. The key performs a cryptographic challenge-response that is bound to the specific website — a fake site cannot intercept a valid response. No code is transmitted that can be intercepted.

    #2

    TOTP Authenticator Apps

    Time-based one-time passwords generated by apps like Google Authenticator, Authy, or 1Password are significantly more secure than SMS codes. The code is generated on-device without a network transaction, making SS7 and SIM swap attacks irrelevant. Phishing remains a risk, but TOTP is a major improvement over SMS.

    #3

    Passkeys

    Passkeys (FIDO2 discoverable credentials) are replacing passwords and 2FA together. Stored in your device's secure enclave and synced across devices via platform credentials (Apple ID, Google Account), passkeys are phishing-resistant, require no codes, and are simpler to use than any other secure authentication method.

    The Migration Path

    Transitioning away from SMS does not require an all-or-nothing change. A practical, incremental approach:

    1. 1Install Signal or Zitto and begin using it for conversations with contacts who also install it.
    2. 2For all accounts that support it, switch from SMS 2FA to an authenticator app — start with email, banking, and any account holding cryptocurrency.
    3. 3Enable passkeys on services that support them (Apple, Google, Microsoft, major banks are rolling these out).
    4. 4If you have high-value accounts, acquire a hardware key and register it as the primary 2FA method.
    5. 5Audit your remaining SMS 2FA accounts annually and migrate each one as TOTP support becomes available.

    Want the full comparison?

    For a detailed breakdown of every major encrypted messaging platform, their protocols, metadata practices, and anonymity features, read our comprehensive guide.

    The Ultimate Guide to Encrypted Messaging in 2026

    Frequently Asked Questions

    Why is SMS not secure?

    SMS is not secure because it was designed in 1985 without encryption, relies on the SS7 signalling protocol which has well-known vulnerabilities allowing interception, is vulnerable to SIM swapping attacks, stores message content on carrier servers, and allows government access with relatively low legal thresholds. Every SMS message you send passes through infrastructure that your carrier — and potentially others — can fully read.

    Can someone intercept my text messages without touching my phone?

    Yes. SS7 attacks allow an attacker with access to a telecom signalling network to intercept SMS messages remotely without any access to your device. IMSI catchers (fake cell towers) can intercept messages in the immediate physical vicinity. Carrier employees with access to internal systems can read messages. None of these attacks require physical access to your phone.

    Is iMessage more secure than SMS?

    Yes, significantly. iMessage uses end-to-end encryption when communicating between Apple devices (the "blue bubble" messages). It is protected against SS7 attacks and carrier interception. However, iMessage is not perfectly secure: iCloud backups can expose message history unless Apple's Advanced Data Protection is enabled, it requires an Apple account, and Apple has complied with law enforcement requests for iCloud data. For the highest privacy, Signal or Zitto are preferable to iMessage.

    Are RCS messages more secure than SMS?

    RCS (Rich Communication Services) — Google's replacement for SMS, now supported natively on iPhone with iOS 18 — offers an improvement over classic SMS in that Google's implementation includes end-to-end encryption for RCS chats between Android devices. However, RCS is not universally encrypted (cross-platform RCS between Android and iPhone initially had limited encryption), metadata is still collected by carriers and Google, and the overall security posture is still significantly weaker than purpose-built encrypted messaging apps like Signal.

    Should I stop using SMS entirely?

    For sensitive communication — anything involving financial information, personal health details, security codes, private relationships, or professionally sensitive content — yes, you should use an end-to-end encrypted alternative. For low-stakes coordination where privacy is not a concern, SMS remains convenient. The practical advice is to use Signal, Zitto, or WhatsApp for all substantive communication, and to migrate SMS 2FA to an authenticator app for all high-value accounts.

    Does using Wi-Fi calling make SMS more secure?

    No. Wi-Fi calling routes your voice calls and SMS messages over the internet rather than traditional cellular networks, but the messages are still delivered through carrier infrastructure at each end. The carrier can still read your SMS messages. Wi-Fi calling provides no meaningful improvement to SMS security and does not protect against SS7 attacks, carrier interception, SIM swapping, or metadata collection.

    Move Beyond SMS Today

    Zitto gives you end-to-end encrypted messaging without requiring a phone number, email address, or any personally identifying information. No metadata logging. No carrier interception. No SIM swap surface.