logo

Google binning SMS MFA at last and replacing it with QR codes

ID: fb4d9ad1-4fdd-5cb7-8089-47f329e0ab7d

STIX ID: report--fb4d9ad1-4fdd-5cb7-8089-47f329e0ab7d

Feed Name: The Register (Security)

Date Published: 2025-02-25

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Google is phasing out SMS one-time passcodes for MFA, citing risks like SS7 interception, SIM swapping, and traffic-pumping fraud, and will shift users toward QR-code-based verification and stronger methods such as security keys. This change aligns with prior guidance from NIST and CISA to avoid SMS for authentication and aims to reduce the attack surface while retaining limited SMS use for identity confirmation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.