SMS 2FA
IT 17 August 2026

SMS 2FA is Going Away & Businesses Need to Prepare

Back to blog

For years, the code texted to your phone has been the everyday face of "extra security." That era is ending. Google is phasing out SMS codes for Gmail in favour of passkeys and authenticator apps, US security standards body NIST reclassified SMS codes as a "restricted" method in 2025, and financial regulators in several countries have set hard deadlines to drop them through 2026. Microsoft and Meta are steering their users the same way.

The reason is simple: SMS is easy to attack. Through SIM swapping, a fraudster ports your number onto their own SIM and receives every code, and modern phishing kits can grab a texted code the instant you type it. This kind of fraud has surged sharply in the UK, and removing the phone network from the login process shuts that whole route down.

Why it matters for your business

This isn't just a consumer story. Your email is effectively the master key to everything else: get into a business inbox and you can reset the password on banking, your CRM, cloud storage and supplier accounts. There's a practical risk too. As platforms like Google switch SMS off by default, staff who never set up an alternative can find themselves locked out of the accounts they need to work, with no warning. Getting ahead of it avoids the downtime and turns a security requirement into a genuine trust signal for your clients.

Passkeys coming to Google Ads

Where it affects you

Many of your everyday tools sit behind a single login, so one change hits several at once:

  • Email and IT: Microsoft 365 (Outlook, Teams, SharePoint) and Google Workspace, plus your hosting, domain and WordPress logins.

  • Marketing: your whole Google stack sits behind one Google account (Ads, Analytics, Search Console, Tag Manager, Merchant Center, Business Profile, YouTube), along with Meta, LinkedIn and Mailchimp.

  • Finance and e-commerce: online banking, Stripe, PayPal, Xero, and your Shopify or WooCommerce admin, the area where regulators are moving fastest.

We're already seeing businesses get caught out by this, usually when a staff member suddenly can't get into their email. Treat it as a bit of quick housekeeping now and you'll barely notice the change. Leave it, and you'll be sorting it out under pressure, often after something's already gone wrong. It's a small, cheap fix that heads off a very expensive problem."

James Dearmer, Rushax

What to move to instead

The good news is that the alternatives are more secure and, once set up, usually quicker to use:

  • Passkeys are the strongest option and where the industry is heading. Unlocked by your fingerprint or face, they're tied to the specific website, so they can't be phished or intercepted.

  • Authenticator apps (such as Microsoft or Google Authenticator) generate codes on the device itself, so there's no text to intercept. A quick, low-friction upgrade.

  • Hardware keys like a YubiKey are the gold standard for your highest-risk accounts, such as finance and admin logins.

Your action plan

  1. Audit where SMS 2FA is still in use across email, banking, marketing tools and anything staff log into daily.

  2. Prioritise email and anything financial first, since they cause the most damage if breached.

  3. Roll out authenticator apps or passkeys across your team, starting with directors and administrators.

  4. Set a date to switch SMS off as a fallback once the alternatives are in place.


Not sure where your business stands? At Rushax we help SMEs across London and Kent tighten up their day-to-day security, from how your team logs in to broader IT support and Cyber Essentials readiness. Get in touch for a straightforward review of your setup.

Rushax

James Dearmer, Rushax

Managing Director, Rushax

Need help with your website?

Get a free consultation with the Rushax team and let us put together a plan for your business.

Get a Free Quote