apple patient
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
  • iPhone 18
  • iPhone 18 Pro
  • iPhone Duo
  • Apple Watch Series 12
  • Apple Watch Ultra 4
  • AirPods 5
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights
No Result
View All Result
apple patient
No Result
View All Result
  • iPhone 18
  • iPhone 18 Pro
  • iPhone Duo
  • Apple Watch Series 12
  • Apple Watch Ultra 4
  • AirPods 5
  • iOS 27
  • iPadOS 27
  • macOS
  • MacBook Neo
  • iPhone 17e
  • AirTags
  • iOS 26
  • iPhone 17
  • MacBook Pro
  • iPadOS
  • iMac
  • Mac mini
  • HomePod
  • Apple TV
  • iPad Pro
  • iPhone Air
  • Apple Vision Pro
  • iPhone 16
  • AirPods 4
  • Apple Watch Ultra
  • HomePod Mini
  • MacBook Air
  • iPad
  • AirPods Max
  • AirPods Pro 3
  • Apple Watch Series 3
  • Mac Studio
  • Studio Display
  • iPad Air
  • iPad mini
  • watchOS 27
  • Apple CarPlay
  • Apple Pay
  • watchOS 26

1 million 2FA SMS intercepted: This method protects you

Milan Jovicic by Milan Jovicic
June 17, 2025 - 2:43 PM CEST
in Apple News
0
2FA Codes Security

Image: Shutterstock / May_Chanikran

WhatsAppFacebookEmail
Threads

If you use 2FA, you probably feel safe. After all, this additional layer of security is supposed to prevent strangers from accessing your accounts, even if they know your password. But now a new report shows that this very security measure has been massively undermined: Approximately one million two-factor authentication codes sent via SMS have been intercepted. And not by random hackers, but by a legitimate mobile phone company with ties to intelligence agencies and surveillance firms. Here's what happened—and how you can better protect yourself.

Two-factor authentication (2FA) works like this: You enter your password and receive an additional code – usually six digits – to confirm your identity. The code can be sent via SMS or generated via an app. The goal: increased security. Good in theory. In practice, however, it has been repeatedly shown that SMS is an insecure transmission method. SMS messages are not encrypted; they travel openly through the mobile network. Anyone with access to certain network technology can read these messages. That's exactly what happened.

What exactly happened: One million 2FA SMS intercepted

According to a report by Bloomberg Businessweek and Lighthouse Reports , around one million text messages containing 2FA codes were intercepted in June 2023. An industry insider provided phone connection data showing that all of these messages were routed through a company called Fink Telecom Services. This company is based in Switzerland but operates internationally and has a history of collaborating with government intelligence agencies and surveillance companies. The intercepted messages contained security codes from a variety of major companies, including Google, Meta (Facebook, Instagram & WhatsApp), Amazon, Signal, Snapchat, Tinder, Binance, and several European banks.

Background monitoring: 2FA SMS redirected

The codes were sent to users in over 100 countries on five continents. This was not a random isolated incident, but rather a systematic redirection and analysis of highly sensitive SMS messages. According to the report, Fink Telecom Services was responsible for routing the messages—that is, how the SMS messages reached the recipient via international networks. The company's CFO claims that Fink merely provides technical infrastructure and is not actively involved in surveillance. Security experts disagree: They have linked Fink to cases in the past in which precisely such SMS codes were intercepted and later used for hacks.

Why SMS codes can be intercepted so easily

The major problem with SMS is the lack of encryption. When you receive an SMS, it is transmitted unprotected through the mobile network. This makes it possible for attackers to intercept the messages – especially if they have access to routing points or international exchanges. And that's where Fink Telecom Services comes in. The company operates such exchanges and is therefore able to access large amounts of SMS data. The security gap is therefore no coincidence, but a structural problem in the mobile network – especially with cross-border messages. The combination of technical infrastructure, outdated protocols, and a lack of encryption makes it possible for external actors to read what should actually remain confidential.

Which providers were affected

Affected were companies that send 2FA codes via SMS as standard. These include:

  • Google (e.g. for Gmail or Google Accounts)
  • Meta (Facebook, Instagram)
  • Amazon.com
  • Signal and WhatsApp (although these apps communicate encrypted, their 2FA SMS runs outside the app)
  • Binance (crypto exchange)
  • Tinder, Snapchat
  • Several large European banks

Most of these providers also offer alternatives to SMS-based 2FA – but continue to use SMS as the default option or as a fallback if users don't use an app.

How you can protect yourself

The most important measure: Stop using SMS for 2FA if you can avoid it. Instead, switch to authentication apps. These generate the six-digit code directly on your smartphone, without sending it over a network. Popular apps include:

  • Authy
  • Google Authenticator
  • Microsoft Authenticator
  • as an Apple user you can also use the Passwords app with its own 2FA system

An even more secure method is the use of so-called passkeys. This eliminates the need for a code altogether—instead, you confirm your identity locally on your device, for example, with Face ID or Touch ID. Login is cryptographically secured, and a password or SMS code is no longer necessary.

  • Forgotten your Apple account password? Here's how to get access
  • Protect your Apple Account: Set up a recovery contact

SMS-2FA is beyond rescue

This interception clearly demonstrates how vulnerable SMS 2FA is. Even with two-factor authentication enabled, you're not safe if the second component—the code—is transmitted over an insecure system. Therefore, you should review all your accounts and switch to app-based authentication or passkeys as quickly as possible. This will take you a few minutes—but it will better protect you against precisely these types of attacks in the long run. If you want to be on the safe side: Stop using SMS for security codes. Never. (Image: Shutterstock / May_Chanikran)

  • WhatsApp launches advertising: Meta uses this data for it
  • iOS 18.6: Apple launches new beta with focus on stability
  • Apple makes it clear: Music is art, not advertising revenue
Make Apfelpatient a preferred source One click – and you'll see us more often on Google
Was this article helpful?
YesNo
Tags: TechPatient
SendShareSend
Share

Our Amazon Storefront

A handpicked selection of products for iPhone, Mac and more – sorted by topic and updated regularly.

Shop Now

This post contains affiliate links (including Amazon). We earn a small commission on qualifying purchases – at no extra cost to you. Learn more on our Partner Program page.

Previous Post

WhatsApp launches advertising: Meta uses this data for it

Next Post

iOS 18.6 Beta shows: Apple is working on the Smart Display

Milan Jovicic

Milan Jovicic

Milan founded Apfelpatient in 2016 and has been responsible for all editorial content since 2018 — news, rumors, guides, and product reviews. Apple devices here are not test units on loan for two weeks but everyday tools: from the iPhone through MacBook Pro, MacBook Air, and iMac to the Apple Vision Pro, at least one device from nearly every product category is in daily use, many of them replaced annually. Every menu path in a guide is verified on the device before it is published.

Related posts

iPad mini 8 and iPad 12: Apple code reveals chips and camera

by Milan Jovicic
September 25, 2026 - 10:48 p.m. CEST
Yellow entry-level iPad seen from the back on a grey stone surface – for the code finding on the iPad mini 8 and iPad 12

iPad mini 8 and iPad 12: Apple's code mentions A20 Pro and A19, a new front camera on the mini, and Apple Intelligence for the entry-level iPad.

Read moreDetails

watchOS 27.2: Code reveals new screenshot preview

by Milan Jovicic
September 24, 2026 - 8:36 p.m. CEST
Apple Watch Ultra with an orange band showing the app view, the device getting the new screenshot preview in watchOS 27.2

watchOS 27.2 includes a new screenshot interface for the Apple Watch: preview, share, and delete, just like on the iPhone. It's currently inactive.

Read moreDetails

Apple TV: Peanuts classics free again for Christmas

by Milan Jovicic
September 24, 2026 - 6:43 p.m. CEST
Charlie Brown holding a small Christmas tree under a starry sky in the snow, a scene from A Charlie Brown Christmas, free again on Apple TV

Three classic Peanuts cartoons are back on Apple TV for the holidays, no subscription required. Plus, there are new specials featuring Snoopy and the Fraggle Rocks.

Read moreDetails

The Wanted Man: Hugh Laurie on Apple TV from January

by Milan Jovicic
September 24, 2026 - 6:19 p.m. CEST
Hugh Laurie as crime boss Felix Carmichael in an evening scene from The Wanted Man on Apple TV

The Wanted Man premieres on January 6, 2027 on Apple TV. Hugh Laurie plays a crime boss who wants to escape – the finale is in February.

Read moreDetails

Apple and Qualcomm extend patent license from 2027

by Milan Jovicic
September 24, 2026 - 6:04 p.m. CEST
Back of an iPhone 18 Pro Max in a burgundy case on a grey surface, covered by the renewed Apple Qualcomm patent license

Apple and Qualcomm are extending their patent license from April 2027. Why this has nothing to do with the modem change and affects Germany.

Read moreDetails
Load More

Categories

  • Apple Insights
  • Apple Rumors
  • Apple News
  • Apple Tips & Tricks
  • iPhone news, rumors and tips
  • Mac and MacBook News
  • Reviews

About APFELPATIENT

APFELPATIENT brings you the latest Apple news, product updates, guides, reviews and tips across the entire Apple ecosystem — from the iPhone to the Mac to the Apple Vision Pro. From the first rumors to confirmed news: researched responsibly.

Follow Apfelpatient

Facebook Instagram YouTube Threads Threads

Company

  • About Apfelpatient
  • Contact
  • Author Profiles

Community

  • Netiquette
  • Push Notifications
  • RSS feed

Legal

  • Legal Notice
  • Privacy Policy
  • Terms of Use
  • Cookie Settings
  • Affiliate Program

Resources

  • Sitemap

© 2026 Apfelpatient. All rights reserved.

No Result
View All Result
  • Home
  • News
  • Rumors
  • Tips & Tricks
  • Reviews
  • Insights

© 2026 Apfelpatient. All rights reserved. Page Directory

Change language to Deutsch