Microsoft warns against SMS authentication as AI-powered phishing grows
Microsoft is urging information technology administrators to gradually move away from SMS messages and phone calls as authentication methods, warning that the rapid development of artificial intelligence is making phishing attacks more convincing and easier to carry out.
The company has advised IT professionals to adopt stronger authentication methods that are designed to resist phishing attempts. According to Microsoft, attackers can increasingly use AI tools to create convincing messages and manipulate users into revealing passwords, verification codes and other sensitive login information.
The growing use of AI is also increasing concerns about SIM-swapping attacks. In these scams, criminals attempt to convince telecommunications providers to transfer a victim's phone number to a SIM card controlled by the attacker. AI does not directly compromise the SIM card, but it can make the social engineering techniques used to obtain personal information more effective.
Microsoft has reported a significant increase in AI-assisted attacks targeting passwords and multi-factor authentication codes. The company says these attacks can achieve higher success rates than many traditional phishing campaigns because they allow attackers to produce more personalized and convincing communications.
For organizations using Microsoft Entra ID, the company has established a gradual transition away from SMS and voice-call authentication. Starting September 1, 2026, users who rely on text messages or voice calls for authentication will be prompted to set up a passkey when signing in. From February 1, 2027, SMS and voice-call authentication will no longer be supported for Entra ID, making alternative authentication methods necessary.
The change also affects the broader direction of Microsoft's security strategy. The company has been encouraging users to adopt passkeys and authentication applications instead of relying on phone-based verification. Passkeys are designed to provide stronger protection against phishing because they use cryptographic credentials rather than codes that can be copied or tricked from users.
Microsoft is also gradually reducing its reliance on SMS for personal accounts used to access services such as Outlook, Xbox and Windows. A final deadline for all personal accounts has not been announced, but users can already strengthen their accounts by setting up a passkey or using Microsoft Authenticator.
The shift reflects a broader transformation in digital security. As AI gives cybercriminals new tools to automate and personalize scams, traditional passwords and SMS-based verification are increasingly viewed as weaker layers of protection. Security specialists are therefore encouraging organizations and individuals to adopt authentication methods that are more resistant to phishing and social engineering.
-
13:25
-
12:16
-
11:40
-
10:34
-
10:17
-
10:12
-
09:58
-
09:41
-
07:57
-
07:41
-
19:15
-
19:00
-
18:41
-
17:49
-
16:16
-
15:54
-
15:39
-
14:00