Interestana
Home/News/Microsoft Urges End to SMS Passwords Amid AI Phishing Threats
Digital Trends••2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Urges End to SMS Passwords Amid AI Phishing Threats

Microsoft Urges End to SMS Passwords Amid AI Phishing Threats

Microsoft is urging IT administrators to transition away from SMS and voice-based multi-factor authentication (MFA) methods, citing the growing sophistication of AI-powered phishing attacks that can exploit these traditional security layers. The technology giant's recommendation, detailed in a recent advisory, highlights a critical shift in cybersecurity strategy as artificial intelligence increasingly enables malicious actors to craft more convincing and harder-to-detect fraudulent communications. These AI-driven attacks can mimic legitimate messages and calls with unprecedented accuracy, making it difficult for users to distinguish between authentic and phishing attempts.

The advisory from Microsoft underscores a broader industry concern that traditional one-time passcodes (OTPs) sent via SMS or delivered through automated voice calls are becoming less secure. Phishing campaigns leveraging AI can now automate the process of intercepting these codes or tricking users into revealing them. This vulnerability poses a significant risk to organizations relying on these methods to protect sensitive data and systems. Microsoft is advocating for a widespread adoption of more robust authentication solutions, with a particular emphasis on passkeys.

Passkeys represent a next-generation authentication standard that utilizes cryptographic key pairs stored on a user's device. Unlike SMS codes, passkeys are resistant to phishing because they are tied to the specific website or application the user is trying to access and are not transmitted over insecure channels. This technology offers a more secure and user-friendly alternative, aiming to eliminate the need for passwords and traditional MFA methods altogether. Microsoft has outlined a phased approach for organizations to migrate from SMS-based authentication to passkeys, encouraging a proactive stance against evolving cyber threats.

The timeline for this transition is crucial for organizations to implement necessary changes and educate their users. While specific dates for a complete deprecation of SMS authentication were not provided, Microsoft's strong recommendation signals an imminent push towards more secure, modern authentication protocols. The company's stance reflects a growing consensus within the cybersecurity community that legacy authentication methods are no longer sufficient in the face of advanced AI threats. By moving towards passkeys and other advanced MFA solutions, businesses can significantly enhance their security posture and protect against the escalating risks of AI-enabled cyberattacks.

Original source — read the full reporting at the publisher:

Read on Digital Trends

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next