ROR Labs cover: 0 phishing successes. One organisation moved more than 85,000 people to security keys and recorded none. The code texted to your phone does not do this.
|

The Two-Factor Code on Your Phone Will Not Stop This

Disclosure: this article contains affiliate links, marked (paid link). If you buy through one we may earn a commission, at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. It costs you nothing and it does not change what we recommend.

Key takeaways · 9 min read

  • Reported U.S. fraud losses reached about $16 billion in 2025, with $3.5 billion from imposter scams.
  • The attack is almost never broken encryption. It is a convincing copy of something you trust.
  • SMS codes can be relayed by a fake page in real time. CISA ranks them last, and they are also the only method vulnerable to SIM swapping.
  • Security keys and passkeys are bound to the web address, so they cannot be handed to a lookalike site. That is the property that matters.

Most online security advice is a list of habits: pick strong passwords, do not click suspicious links, be careful. It is the equivalent of telling people to drive carefully instead of fitting seatbelts. It puts the entire burden on a human being being alert at the exact moment somebody is professionally trying to catch them off guard.

There is a better approach, and it has an unusually clean piece of evidence behind it. One large organisation stopped relying on employees noticing fake login pages, changed the mechanics of how logging in works, and recorded zero successful phishing attacks across more than 85,000 people.

This article is about that mechanism, why the two-factor authentication most people already use does not provide it, and what the fraud numbers say about where the money is actually going.

A wet street at dusk with lit shopfronts and their reflections doubled in the puddles below.
One of these is the street. The other only looks like it.

The scale, and where it moved

Reported U.S. fraud losses, 2025

Federal Trade Commission data, published 15 June 2026. These are only the losses people reported.

$16Btotal reported fraud losses in 2025 — up about 25% on 2024
$3.5Bof it from imposter scams alone, roughly one in three fraud reports
Imposter scam losses have grown nearly three times since 2020. Bank impersonators and government impersonators accounted for about $920 million each.

Source: Federal Trade Commission, “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025,” 15 June 2026.

The word imposter is doing a lot of work there. It means someone contacted you claiming to be your bank, a government agency, a delivery company, or a relative. Not a mysterious hacker breaking encryption — a person or a script pretending to be an institution you already trust, and asking you to do something ordinary.

That matters because it tells you where the defence has to sit. If the attack is “convince a human that this login page is real,” then any defence that depends on the human spotting the fake is defending on the attacker’s home ground.

Why the code texted to your phone does not save you

A folded slip of paper pushed halfway under a closed door onto a hallway floor.
A code is only ever information. It can be passed along.

Almost everyone now has two-factor authentication on something. Most of it is the six-digit code sent by text message. It is far better than nothing, and it is also the weakest option available, for a reason that becomes obvious once you see it.

A code is just information. If a fake page can persuade you to type your password into it, the same page can persuade you to type the code into it, and relay both to the real site within the sixty seconds the code is valid. The code changes nothing about who is standing in the middle.

How U.S. cybersecurity authorities rank the options

CISA’s implementation guidance, October 2022. Phishing resistance is the property that matters.

MethodStops phishing?Stops SIM swap?CISA position
Security key / passkey (FIDO)YesNot applicableThe gold standard
Authenticator app codeNoYesAcceptable middle tier
Push with number matchingNoYesBetter than plain push
Push, tap to approveNoYesVulnerable to push bombing
SMS or voice codeNoNoLast resort only
Only the top row is described as phishing-resistant. Everything below it can be relayed by a convincing fake page in real time.

Source: Cybersecurity and Infrastructure Security Agency, “Implementing Phishing-Resistant MFA,” fact sheet, October 2022.

What a security key does differently

A security key — and a passkey, which is the same technology stored on your phone or laptop instead of a separate object — does not send a secret you could be tricked into forwarding. It performs a cryptographic handshake that is bound to the website address.

That binding is the whole trick. Your key registered itself with the real domain. When a lookalike domain asks it to log in, the key does not recognise the address, and it simply will not produce a signature. There is nothing for you to notice, no judgement call to make and no way to be persuaded. The check happens below the level where persuasion works.

Where each method breaks — and where the key does not

The same attack, run against two setups.

SMS CODE — the fake site just passes it along you fake pagelooks identical real bank logged in as you SECURITY KEY — the address does not match, so nothing is produced your key fake pagewrong domain no signature nothing to steal, nothing to relay
In the top row nothing technically failed — every component worked exactly as designed. The only broken part was a person’s ability to tell two identical-looking pages apart.

Source: mechanism as described in CISA, “Implementing Phishing-Resistant MFA” (2022); FIDO Alliance technical documentation.

The deployment result that made this the recommendation

Google required physical security keys for all staff.

85,000+employees required to use a physical security key
0successful phishing attacks against them since the requirement began
A single organisation is not a controlled trial, and a company with a security team is not a household. But zero, at that headcount, against attackers who target that company constantly, is a strong result.

Source: FIDO Alliance, Google case study (published 28 January 2019; deployment from around 2017).

The accounts that are worth protecting first

You do not need to do this to every account, and trying to would be a good way to give up. Almost all of the damage flows through a small number of accounts, because they are the ones that can reset the others.

Protect these four, in this order

Ranked by how much else falls over if this one is taken.

1. YOUR EMAILThe master key. Whoever controls it can request a password reset on nearly everything else you own. This is the single highest-value account you have, and most people protect it worse than their bank.
2. YOUR PHONE ACCOUNTA SIM swap moves your number to someone else’s device, which hands them every SMS code you rely on. Ask your carrier for a port-out PIN or account lock.
3. BANKING AND PAYMENTSThe obvious one, and the one people already worry about — but it sits below email, because email can often reset it.
4. CLOUD STORAGE / APPLE OR GOOGLE IDPhotos, documents, backups, and often the recovery route back into the device itself.

Sources: account-recovery dependency structure described in CISA consumer guidance (cisa.gov/MFA); FTC imposter scam reporting (2026).

Notice how much of that list is free. Turning on a passkey costs nothing. Asking your mobile carrier to lock your number against transfer costs nothing and takes one phone call. Those two moves address more risk than any purchase in this article.

Passkeys are the same protection without the shopping

A physical key is not the only way to get phishing resistance any more. A passkey is the identical cryptographic mechanism, with the secret stored on a phone or computer and unlocked by a fingerprint, face or device PIN. It is built into current iPhones, Android phones, Macs and Windows machines, and a growing number of banks, email providers and shops accept it.

Passkey or physical key?

Same protection, different trade-offs.

FreePasskeyAlready on your devices. Syncs across them, so losing one phone is recoverable. The right default for almost everybody, and the correct first step.
PhysicalSecurity keyA separate object, not tied to a phone or a platform account. Worth it if you are a plausible target, want a recovery method independent of your devices, or need one that works across ecosystems.
Buy a physical key only after you have turned on passkeys where they are offered — the free step is the one with the bigger effect.

Source: FIDO Alliance specifications; CISA phishing-resistant MFA guidance (2022).

If you want the physical version

Only after the free steps above. Buy two — one to use, one stored elsewhere as a backup.

FIDO2 SECURITY KEYCheck the connector matches your devices (USB-C, USB-A, NFC for phones). The standard to look for is FIDO2 / WebAuthn.
Browse on Amazon →
A SECOND KEY AS BACKUPThe realistic failure mode is not theft, it is loss. Register two keys on each account and keep the spare somewhere else.
Browse on Amazon →

We are not linking antivirus subscriptions, “identity theft protection” services, or VPNs here. None of them prevent the attack described in this article — a person typing a real password into a convincing fake page — and bundling them into a piece about phishing would blur a distinction that matters. Two free actions (a passkey, and a port-out lock on your phone number) outperform all of them for this specific risk.

A figure at a warm-lit doorway in the early evening, checking the house number before the door opens.
The key checks the address before it opens anything. You do not.

Questions people ask

What if I lose the key, or my phone?

This is the correct thing to worry about, and it is why every account offers backup options. Register a second key, save the recovery codes on paper somewhere physical, and keep one alternative method enabled. Passkeys that sync through your Apple or Google account survive a lost phone automatically.

Is a password manager still worth it?

Yes, for a different problem. Phishing resistance stops someone using your password on a fake page; a password manager stops one breached site’s password unlocking twenty others. They solve different failures and both are worth having. Most now store passkeys as well.

My bank only offers SMS codes. What can I do?

Then use them — SMS is far better than nothing, and CISA says so explicitly while ranking it last. Do the things you can control: a port-out lock with your carrier closes the SIM-swap route, and protecting the email account attached to the bank closes the reset route.

Someone called saying they were from my bank’s fraud team. How do I know?

You cannot, from the call itself — caller ID is trivially faked, and this is the single largest imposter category in the FTC data. The rule that always works: hang up and call back on the number printed on your card or on the bank’s official website. A real fraud department will never object. Nobody legitimate needs you to move money to a “safe account”, and that phrase is close to diagnostic of a scam.

The short version

  • Reported U.S. fraud losses reached about $16 billion in 2025, with $3.5 billion from imposter scams.
  • The attack is almost never broken encryption. It is a convincing copy of something you trust.
  • SMS codes can be relayed by a fake page in real time. CISA ranks them last, and they are also the only method vulnerable to SIM swapping.
  • Security keys and passkeys are bound to the web address, so they cannot be handed to a lookalike site. That is the property that matters.
  • Google recorded zero successful phishing attacks across 85,000+ staff after requiring physical keys.
  • Protect email first — it can reset almost everything else — then your phone account, then banking.
  • The two highest-value actions are free: turn on passkeys, and ask your carrier for a port-out lock.
  • For phone calls: hang up and dial the number on your card. Always available, always works.

On the links above: some are affiliate links, marked (paid link). If you buy through one we may earn a commission at no additional cost to you. As an Amazon Associate I earn from qualifying purchases. We link to product searches rather than specific items so recommendations do not break as models change, and we say plainly when we are choosing not to link something. Full policy: Affiliate Disclosure.

Sources

  • Federal Trade Commission. “FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025.” Press release, 15 June 2026.
  • Cybersecurity and Infrastructure Security Agency. “Implementing Phishing-Resistant MFA.” Fact sheet, October 2022.
  • Cybersecurity and Infrastructure Security Agency. “More than a Password” (cisa.gov/MFA).
  • FIDO Alliance. Google case study on security key deployment, 28 January 2019.

Similar Posts