Your bank may stop texting you six-digit codes

If you bank online, you probably know the routine. You enter your password and then wait for a six-digit code to arrive by text. That extra step is supposed to help prove you are really you. Unfortunately, scammers have learned how to turn those codes against us.

A fake bank representative may call and persuade you to read the code aloud. A phishing site can trick you into typing it in. A SIM-swap attack can give a criminal control of your phone number, potentially putting those texted security codes within reach.

The Federal Trade Commission says people reported losing $15.9 billion to fraud in 2025, compared with $12.5 billion in 2024. Imposter scams were the most frequently reported fraud category in 2025, accounting for more than $3.5 billion in reported losses.

Now, a new type of phone-based verification could eventually make those texted codes much less common. Glide.id has launched the public beta of MagicalAuth, a cryptographic authentication system available across AT&T, T-Mobile and Verizon on iOS and Android. Banks and other services still have to integrate the technology before you would encounter it during a login.

Here’s how the system works and what it could mean for the way you log in to your bank down the road.

New! Free live CyberGuy class: Protect Your Money From Today’s Biggest Threats

Join us Saturday, Aug. 29, at 10 a.m. ET for a free CyberGuy LIVE class covering five simple steps to help defend yourself against AI scams, fraud, identity theft and financial hacks. Kurt “CyberGuy” Knutsson will explain how to set up bank alerts, strengthen your account logins, protect your phone number, freeze your credit and help secure your retirement savings against unauthorized transfers. No technical experience is needed. You’ll also receive our financial protection checklist, and every registrant will get a link to the class recording afterward.

Reserve your free spot today at CyberGuyLive.com.

YOUR FAMILY COULD BE ONE PHONE CALL FROM A BANK SCAM

Your bank sends a texted one-time password, often called an SMS OTP, to your phone and expects you to enter it to prove you have access to that number. The problem is that the code passes through your hands. “A texted code is a shared secret,” Eran Haggiag, founder and CEO of Glide.id, told CyberGuy. “It gets created, sent across the network, and then a person has to read it and type it in, and every one of those steps is a place it can be intercepted or tricked out of someone.”

MagicalAuth takes a different approach. Rather than sending you a code, Glide says the system relies on cryptographic credentials associated with the SIM or eSIM in your phone. Eran said, “It relies on a secret that’s built into the SIM in your phone and never leaves it, similar to the chip in a credit card.”

During authentication, the bank or service can use the carrier network to confirm that the expected SIM is present instead of asking you to relay a secret. “That’s what lets the carrier confirm it’s really your SIM,” Eran said.

Glide says each SIM contains a carrier-issued cryptographic key. MagicalAuth uses that key to answer a mathematical challenge during authentication. “There is no app to download, no setting to change, and nothing for the consumer to enroll in or configure,” Eran told CyberGuy.

Instead, the bank or service integrates the system on its side. The first time you encounter it, Eran says you would see a consent screen explaining that your phone number and possession of your device are being used to verify your identity. After that, the process is designed to happen behind the scenes. Eran said that, unlike SMS, “there is no code sent and nothing to type in.”

“After that, verification happens quietly in the background in a fraction of a second, so the experience is faster and smoother than waiting on a text,” he said. For you, that could mean fewer moments spent staring at your Messages app waiting for a bank code to arrive.

A SIM-swap scam raises an obvious question about this technology. If the SIM is helping prove your identity, what happens when a crook gets your number transferred to another SIM?

In a SIM-swap attack, a criminal gets control of your phone number by moving it to another SIM or eSIM. Your phone may suddenly lose cellular service while calls and texts start reaching the attacker’s device. We recently followed a real case on The CyberGuy Report podcast where a sudden loss of phone service led to a SIM swap and thousands of dollars being stolen.

Glide says MagicalAuth looks for recent SIM changes before allowing authentication. “We monitor for SIM changes in real time, so we know the moment a number moves to a new SIM,” Eran said. “When that happens, we don’t allow the new SIM to authenticate for a short window.”

That temporary pause is designed to give the legitimate owner time to notice the problem and recover the number. “So a stolen number stops being enough on its own to take over your accounts,” Eran said.

AT&T says the carrier network can also provide information about recent SIM activity before a sensitive login goes through. “From the carrier side, the key is that we can help verify what is happening on the network before a login is approved,” Shawn Hakl, SVP and head of product at AT&T Business, told CyberGuy. “If a phone number was recently moved to a new SIM or eSIM, that is an important signal.”

A bank could use that information to require another identity check or temporarily pause an action. “That matters because SIM-swap fraud often depends on speed,” Shawn said. “A scammer is trying to move your number and use it before you realize your phone stopped working.”

YOUR MICROSOFT TEXT CODES ARE GOING AWAY

Yes. Stronger authentication will not make social engineering disappear. A scammer can still pretend to work for your bank. AI-generated voices can make those calls more convincing too. I’ve also talked with JPMorgan Chase’s head of scam prevention about how bank scammers manipulate people in real time and what families can do to stop them on The CyberGuy Report podcast.

MagicalAuth is designed to take one powerful piece of ammunition away from the scammer: the one-time code. “They can’t reuse a stolen code, because there is no code to steal, and they can’t phish something the user never sees or types,” Eran said.

There is still a limit to what this protection can do. “It does not make fraud impossible, no security does,” Eran said. A crook could still persuade someone to send money or approve a transfer themselves. That is a different kind of scam because the real account holder is authorizing the transaction.

“What it doesn’t yet solve is a scammer tricking you into approving a transfer yourself, the way romance or investment scams do,” Eran said. So, your judgment still counts. Better login security can make account takeover harder, but it cannot stop a scammer from manipulating you into moving money yourself.

Getting a new phone, replacing a SIM or switching to an eSIM can change the information the carrier sees. That may trigger another verification check.

“If a customer gets a new phone, replaces a SIM or activates an eSIM, a carrier may need to re-check that the phone number and device are still properly matched before allowing a sensitive login or transaction,” Shawn said. In normal situations, Shawn says that check should happen in the background.

However, if something does not match, the bank or app could ask you to verify your identity another way until the change is confirmed. “That extra step may feel like a little friction, but it is there for a reason,” Shawn said. “It helps prevent a fraudster from moving your number to a new SIM and immediately using it to get into your accounts.”

Not yet. Glide says MagicalAuth works across iOS and Android through AT&T, T-Mobile and Verizon, but that does not mean every wireless customer will be supported. Eran says some MVNOs, smaller carriers and many prepaid users are not supported yet.

The age of your phone may not be the deciding factor either. “The experience depends less on the age of the phone and more on whether the customer’s carrier, plan and the app they are using are supported,” Shawn said.

There may also be times when a network check cannot be completed. “In those cases, the bank or app should have a fallback identity check, so the legitimate customer is not locked out,” Shawn said.

If your wireless carrier is helping verify a bank login, you may wonder what information is being shared. AT&T says the goal is to provide a verification signal without handing over more customer information than necessary. “Privacy has to be central to how this works,” Shawn said. “The point of these APIs is verification, not sharing more personal information than necessary.”

In a typical flow, a bank or app asks whether a phone number can be verified against information available through the carrier network. Shawn described the response this way: “It is closer to a yes-or-no trust signal than a transfer of customer data.”

AT&T says the capabilities provide information about the service and SIM, rather than personal information about the customer. That network signal can then become one part of the bank’s decision about whether a login should proceed.

Wireless carriers already have access to network signals that banks cannot see on their own. For example, a carrier can know that a phone number was recently moved to another SIM. Now, network APIs can allow trusted services to use some of those signals during authentication. “What’s changed is that we’re now bringing that same network-level intelligence into the way people verify their identities online,” Shawn said.

For banks, that provides another way to judge whether the phone being used during a login matches what the network expects. For you, the interesting part is that the added check could happen without another app or another code to type.

There is no universal rollout date. Glide has made MagicalAuth available to businesses and developers, but banks have to adopt it individually. “Banks have to implement this on their end, and that’s starting to happen now with some of the biggest and most innovative banks,” Eran said.

Glide’s longer-term goal is to move supported users away from SMS authentication rather than leaving text messages available as the easy fallback. “The intent is for this to be the authentication method for supported numbers, not one option among many,” Eran said.

Your bank will decide whether and when it adopts SIM-based verification. Until then, you can tighten the security around accounts that still rely on texted codes.

If your bank or another sensitive account supports passkeys, consider using one. Passkeys are designed to resist phishing because you do not have a code or password that can be copied into a fake login page. Eran also recommends using passkeys while banks continue relying on one-time codes.

Set up a PIN or password with your carrier. Also check whether your provider offers a number lock or port-out protection feature. Those safeguards can make it harder for someone to move your number to another carrier or SIM without permission.

If your bank still sends security codes by text, keep them to yourself. If someone calls claiming to be from your bank and asks for one, hang up. Then contact your bank using the official number on its website, app or the back of your card. We’ve seen how convincing this type of manipulation can become. In one case covered on the podcast, a woman drove to her bank with a scammer still on the phone and nearly withdrew $15,000.

If your phone unexpectedly loses cellular service, contact your carrier. It could be an ordinary outage, but it can also be a warning sign that someone has tried to move your number to another SIM.

If a scammer gets enough of your personal information, the damage can extend beyond one bank login. An identity theft protection service can monitor for signs that your information is being misused and help you respond if something goes wrong. You can also freeze your credit for free with the three major credit bureaus to make it harder for someone to open new accounts in your name. See my tips and best picks on Best Identity Theft Protection at Cyberguy.com

SIM-based verification can make stolen text codes less useful, but scammers can still come after you through phishing links and malicious websites. Strong antivirus software can help detect malware and warn you about some dangerous links before they compromise your device or personal information. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com

Scammers can use details found online to make fake bank calls and other impersonation attempts sound more convincing. A data removal service can help reduce the amount of personal information available on people-search sites and data broker databases. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com

I’ve warned many times about fake bank calls where someone tells you there is suspicious activity on your account. Before long, they’re asking for the security code that just landed on your phone. For me, the promising part of SIM-based verification is pretty simple. If that code never shows up, a crook cannot talk you into reading it back. I also like that this approach does not ask you to install another app or become your own security expert. If your bank adopts it, the heavy lifting happens between the bank and the carrier network. But I would not lower my guard. A convincing scammer can still talk you into moving money yourself, and AI-generated voices can make those conversations harder to spot. For account takeover, though, getting rid of the six-digit code could take away one of the easiest tricks in a scammer’s playbook.

Would you feel safer if your bank stopped texting security codes and went with this sort of technology? Let us know by writing to us at Cyberguy.com

Sign up for my FREE CyberGuy Report

Copyright 2026 CyberGuy.com. All rights reserved.

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Post