Back to news
Cybersecurity Alert
August 1, 2026 by EmailMeNow IT Consulting

National Banks Still Fail MFA — SMS Dominates Over YubiKey and Authenticator Apps

Public MFA docs for Chase, Bank of America, Wells Fargo, U.S. Bank, Capital One, and Citi show phone SMS codes still dominate. None advertise Google Authenticator / Proton Pass TOTP; Bank of America is the clear FIDO security-key standout. Domain audits (ideal 100%): chase.com 79%; citi.com 50% — none at 100%.

Source: EmailMeNow research

NewsBanksMFAYubiKeyAuthenticator AppsSIM SwapFinancial ServicesCybersecurity
SMS bank code on a phone marked weak beside a hardware security key and authenticator app

Phone-number multi-factor authentication is still the default at most national banks — and under our grading rules that is a fail. SIM-swap and SS7 / number-port abuse have a long public history of stealing SMS one-time codes. We checked whether consumer online banking advertises YubiKey-class FIDO security keys or standard authenticator-app TOTP (Google Authenticator, Proton Pass, and peers). Almost nobody offers the open TOTP path. Hardware keys are rare.

Domain security is a separate control plane. Fresh audit.emailmenow.com scores on August 1, 2026 show none of these six banks at the 100% ideal — even when MFA marketing looks polished.

Why the stakes rose (IBM / Ponemon 2026): financial services averaged USD 6.29M per breach, and AI-driven attacks concentrated on critical sectors including finance. MFA fatigue / helpdesk social engineering averaged USD 5.23M. Details: IBM Cost of a Data Breach 2026.

For Texas regional banks, see the companion scorecard: Texas banks MFA — SMS Secure Access Codes vs YubiKey.

SMS bank code on a phone marked weak beside a hardware security key and authenticator app

How we graded MFA

Public consumer (and clearly labeled business) documentation only — not a logged-in mystery shop of every account type. Methods change; re-check your bank before you rely on this table.

GradeMeaning
FailDocumented consumer second factor is primarily SMS / voice / phone OTP (SIM-swap class)
PartialBetter than SMS alone (bank app push, proprietary soft token, passkeys) but no standard TOTP and no YubiKey/FIDO key
Pass (TOTP)Self-serve Google Authenticator / Proton Pass-style OATH TOTP for login
StrongConsumer FIDO2 / FIDO security key (YubiKey-class) for sign-in or high-risk steps

Phone MFA = Fail in this scorecard even when the bank also offers biometrics or passkeys. Passkeys help phishing resistance for login; they do not erase an SMS-only second-factor path when that is what the bank documents for “2-step verification.”

MFA scoreboard tiers: SMS fail, authenticator pass, hardware key strong

National banks — MFA support

BankYubiKey / FIDOAuthenticator TOTPPasskeysPhone OTPMFA grade
Bank of America
bankofamerica.com
Yes — FIDO USB security key (official)NoLimitedYes (SMS)Strong with key; Fail on SMS
Chase
chase.com
No (retail)NoYesYes (phone/email)Fail (phone) / Partial (passkeys)
Wells Fargo
wellsfargo.com
No; optional RSA SecurIDNoYesYes (text/push/call)Fail (phone) / Partial (passkeys)
U.S. Bank
usbank.com
NoNoYesYes — OTP to mobile (KB)Fail (phone) / Partial (passkeys)
Capital One
capitalone.com
NoNo — app push onlyYes (docs)Yes (SMS)Fail (phone) / Partial (passkeys + app push)
Citi
citi.com
No clear retail YubiKeyNo clear retail TOTPLimitedYes (SMS)Fail

Takeaway: Only Bank of America clearly documents a consumer FIDO security key path that a YubiKey owner can buy and register. None of these six advertise self-serve Google Authenticator / Proton Pass TOTP for retail login. Chase, Wells, U.S. Bank, and Capital One lean on passkeys plus phone OTP / app push — better than passwords alone, still a Fail under our SIM-swap rule when SMS/voice is the documented 2-step method.

Why SMS MFA fails this scorecard

RiskWhy phone OTP loses
SIM swap / port-outAttacker takes the number → receives the bank’s SMS code
SS7 / SMS interceptionCodes travel over carrier messaging, not an end-to-end authenticator
Social engineeringVictims are tricked into reading codes to “bank fraud” callers
Shared recoveryPhone number often resets email + bank + password manager

CISA and industry guidance treat phishing-resistant MFA (FIDO/WebAuthn security keys and well-implemented passkeys) as the top tier. Authenticator-app TOTP is the practical middle for apps that refuse hardware keys. SMS is the bottom tier that still gets labeled “MFA.”

Independent cybersecurity audits

EmailMeNow domain audits on August 1, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture — not whether your login screen offers a YubiKey.

BankDomainOverallIdentityTransportWebsiteRisk
JPMorgan Chasechase.com79%75%15%94%Good
Bank of Americabankofamerica.com70%50%45%92%Good
U.S. Bankusbank.com68%90%15%37%Above Average
Wells Fargowellsfargo.com67%50%15%87%Above Average
Capital Onecapitalone.com58%60%15%45%Average
Citibankciti.com50%40%15%45%Average

Audit links: chase.com · bankofamerica.com · usbank.com · wellsfargo.com · capitalone.com · citi.com

Pattern: Strong websites do not equal strong MFA. Chase leads at 79% with 94% website — still 15% transport. Citi trails at 50% overall while MFA docs still center on SMS OTP.

Cybersquat / lookalike scan

DoH BEC-profile scans (registered-only) on key national brands:

BrandCheckedTo reviewBEC stagingExample threats
chase.com118962chase.io, chasen.com
bankofamerica.com2421751bankofamer1ca.com (MX)
wellsfargo.com1941192weilsfargo.com, wellsfargo-secure.com

National bank brands sit in a dense lookalike space. SMS MFA fails harder when customers can also be phished from wellsfargo-secure.com-style hosts.

What customers should do

  1. Prefer FIDO / security keys where offered (Bank of America USB security key today; ask other banks for FIDO2).
  2. Turn on passkeys at Chase, Wells Fargo, U.S. Bank, and Capital One when available — phishing-resistant login beats password + SMS.
  3. Do not treat SMS as “good MFA.” Use it only if the bank offers nothing stronger; lock your mobile number (carrier PIN / port freeze).
  4. Ask product teams for Google Authenticator / Proton Pass TOTP — absence is a product choice, not a physics limit.

When a bank documents YubiKey / FIDO or you need open TOTP / passkeys elsewhere (email, password managers), these are practical options:

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.


Sources: Bank of America USB Security Key; Chase How we protect you; Wells Fargo 2FA / Passkeys; U.S. Bank two-step verification / Passkeys; Capital One Mobile App Verification / Passkeys. Independent EmailMeNow domain audits and cybersquat scans August 1, 2026. MFA grades reflect public documentation, not a private account enumeration. Domain scores: audit.emailmenow.com only.