Text-message codes are the most familiar form of multi-factor authentication, and they are far better than a password alone. But they have a known weakness: they depend on the security of a phone number, and phone numbers can be stolen. The attack is called SIM swapping, and healthcare organizations that rely on SMS codes for email and remote access should understand it.
Your phone number is tied to a SIM card, or an electronic equivalent, issued by your mobile carrier. In a SIM swap, a criminal convinces the carrier to move your number to a SIM or device they control. Once that happens, calls and text messages meant for you go to the attacker's phone, including the one-time codes used to sign in or reset passwords.
Attackers typically do not hack the phone. They target the process around it:
Social engineering of the carrier. They contact customer service or a store, pretend to be the account holder and claim to have lost a phone.
Insider help. In some cases, a carrier employee has been bribed or tricked.
Gathering personal details. They use information from past data breaches, social media or phishing to answer verification questions.
Port-out requests. They request to transfer the number to another carrier, using stolen account details.
The attack is usually combined with a stolen password. The attacker already knows or has phished the username and password, then uses the swapped number to receive the text code and complete the login.
An administrator, billing manager or executive whose email is protected only by SMS codes is an attractive target. Control of their email can enable password resets for other systems, fraudulent payment requests or access to patient information. Staff often use personal phones for work codes, which places part of your security in the hands of a mobile carrier you do not manage.
A phone suddenly loses service or shows "SOS only" for no clear reason
Unexpected texts or emails about account changes or carrier activity
Alerts about sign-in attempts the person did not make
Friends or coworkers receiving odd messages from the person's number
If someone notices these, they should contact the carrier immediately from another phone, then change passwords from a secure device.
Apps that generate time-based codes on the device are not tied to the phone number, so a SIM swap does not give the attacker the code. They are a major improvement and widely supported.
Some authentication apps send a prompt to approve a sign-in, and require the user to enter a number shown on screen. This resists accidental approvals, though staff should be trained to deny prompts they did not start.
Small physical keys that plug in or tap to a device are among the strongest options, because they resist phishing, not only SIM swapping. They are well suited to administrators and other high-risk roles.
Passkeys replace passwords with cryptographic credentials stored on a device, and support is growing across services. Evaluate them where your systems support them.
Even if you keep SMS for some uses, add protections:
Ask carriers about account PINs or port-out protection, and enable them
Use a strong, unique PIN on the mobile account
Limit personal information shared publicly
Use a business-owned phone number for sensitive accounts where practical
Avoid using the same number for high-value accounts and public contact
Identify which accounts rely on SMS, starting with email, remote access and financial systems.
Move administrators and executives to hardware keys or app-based methods first.
Roll out authenticator apps to all staff, with simple instructions and help desk support.
Keep SMS only as a last-resort fallback, or disable it where you can.
Protect the account recovery process, since attackers target "forgot password" flows.
Train staff to report sudden loss of cell service immediately.
SMS-based MFA still stops many attacks, including the common reuse of stolen passwords. The goal is not to abandon it overnight in a panic, but to move toward stronger methods in order of risk.
UnityCare IT helps healthcare and senior-living organizations in Oklahoma, Texas and Arkansas roll out stronger multi-factor authentication, with a focus on the accounts that would do the most damage if taken over.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172