August 24, 2026

New Security Measures for Online Banking

If you bank online, you’re familiar with receiving a six-digit code via text when logging in. This step is meant to verify your identity, but scammers have found ways to exploit these codes. They might pose as a bank representative asking you to share the code or use phishing tactics to trick you into entering it on a fake site. SIM-swap attacks allow criminals to take control of your phone number, giving them access to these security codes.

Rising Fraud Costs

The Federal Trade Commission reports losses of $15.9 billion to fraud in 2025, up from $12.5 billion in 2024. Imposter scams were the most common, with losses over $3.5 billion.

New Authentication Method

Glide.id’s MagicalAuth, a cryptographic system, is in public beta on major U.S. carriers for iOS and Android. This new method could reduce the use of texted codes. It uses cryptographic credentials tied to your phone’s SIM or eSIM without requiring you to relay a security code.

The Process

The system uses cryptographic keys in your SIM for authentication. Banks or services incorporate the system, and users consent to having their phone number and device used for identity verification. This happens seamlessly, avoiding the need to type in a code.

Tackling SIM-Swap Fraud

SIM-swap scams redirect your phone number to another device, potentially resulting in account takeovers. MagicalAuth detects recent SIM changes and temporarily pauses authentication, allowing the rightful owner to regain control.

“From the carrier side, the key is that we can help verify what is happening on the network before a login is approved,” said Shawn Hakl from AT&T.

Ongoing Challenges and Future Adoption

While this technology could prevent code theft, scammers may still use social engineering. MagicalAuth doesn’t involve apps or complex settings, simplifying its implementation. However, not all phones or carriers support it yet.

Protective Steps You Can Take

  • Use a passkey: If available, this can resist phishing attempts.
  • Secure your wireless account: Set a PIN or use port-out protection with your carrier.
  • Keep codes private: Never share verification codes, even if someone calls claiming to be your bank.
  • Monitor service disruptions: Contact your carrier if you lose cellular service unexpectedly.
  • Consider identity theft protection: This monitors suspicious activity and helps manage potential misuse.
  • Deploy strong antivirus protection: This will help detect malware and suspicious links.
  • Reduce personal information online: Consider a data removal service to limit scammers’ access to your information.

Kurt’s analysis highlights the potential for improved security with SIM-based verification, eliminating the need for texted codes. However, scammers could still trick you into transferring money yourself.

Would this technology make you feel safer? Share your thoughts at Cyberguy.com.

TAGS: