Phone-number multi-factor authentication is still the default at most national banks — and under our grading rules that is a fail. SIM-swap and SS7 / number-port abuse have a long public history of stealing SMS one-time codes. We checked whether consumer online banking advertises YubiKey-class FIDO security keys or standard authenticator-app TOTP (Google Authenticator, Proton Pass, and peers). Almost nobody offers the open TOTP path. Hardware keys are rare.
Domain security is a separate control plane. Fresh audit.emailmenow.com scores on August 1, 2026 show none of these six banks at the 100% ideal — even when MFA marketing looks polished.
Why the stakes rose (IBM / Ponemon 2026): financial services averaged USD 6.29M per breach, and AI-driven attacks concentrated on critical sectors including finance. MFA fatigue / helpdesk social engineering averaged USD 5.23M. Details: IBM Cost of a Data Breach 2026.
For Texas regional banks, see the companion scorecard: Texas banks MFA — SMS Secure Access Codes vs YubiKey.

How we graded MFA
Public consumer (and clearly labeled business) documentation only — not a logged-in mystery shop of every account type. Methods change; re-check your bank before you rely on this table.
| Grade | Meaning |
|---|---|
| Fail | Documented consumer second factor is primarily SMS / voice / phone OTP (SIM-swap class) |
| Partial | Better than SMS alone (bank app push, proprietary soft token, passkeys) but no standard TOTP and no YubiKey/FIDO key |
| Pass (TOTP) | Self-serve Google Authenticator / Proton Pass-style OATH TOTP for login |
| Strong | Consumer FIDO2 / FIDO security key (YubiKey-class) for sign-in or high-risk steps |
Phone MFA = Fail in this scorecard even when the bank also offers biometrics or passkeys. Passkeys help phishing resistance for login; they do not erase an SMS-only second-factor path when that is what the bank documents for “2-step verification.”

National banks — MFA support
| Bank | YubiKey / FIDO | Authenticator TOTP | Passkeys | Phone OTP | MFA grade |
|---|---|---|---|---|---|
Bank of Americabankofamerica.com | Yes — FIDO USB security key (official) | No | Limited | Yes (SMS) | Strong with key; Fail on SMS |
Chasechase.com | No (retail) | No | Yes | Yes (phone/email) | Fail (phone) / Partial (passkeys) |
Wells Fargowellsfargo.com | No; optional RSA SecurID | No | Yes | Yes (text/push/call) | Fail (phone) / Partial (passkeys) |
U.S. Bankusbank.com | No | No | Yes | Yes — OTP to mobile (KB) | Fail (phone) / Partial (passkeys) |
Capital Onecapitalone.com | No | No — app push only | Yes (docs) | Yes (SMS) | Fail (phone) / Partial (passkeys + app push) |
Citiciti.com | No clear retail YubiKey | No clear retail TOTP | Limited | Yes (SMS) | Fail |
Takeaway: Only Bank of America clearly documents a consumer FIDO security key path that a YubiKey owner can buy and register. None of these six advertise self-serve Google Authenticator / Proton Pass TOTP for retail login. Chase, Wells, U.S. Bank, and Capital One lean on passkeys plus phone OTP / app push — better than passwords alone, still a Fail under our SIM-swap rule when SMS/voice is the documented 2-step method.
Why SMS MFA fails this scorecard
| Risk | Why phone OTP loses |
|---|---|
| SIM swap / port-out | Attacker takes the number → receives the bank’s SMS code |
| SS7 / SMS interception | Codes travel over carrier messaging, not an end-to-end authenticator |
| Social engineering | Victims are tricked into reading codes to “bank fraud” callers |
| Shared recovery | Phone number often resets email + bank + password manager |
CISA and industry guidance treat phishing-resistant MFA (FIDO/WebAuthn security keys and well-implemented passkeys) as the top tier. Authenticator-app TOTP is the practical middle for apps that refuse hardware keys. SMS is the bottom tier that still gets labeled “MFA.”
Independent cybersecurity audits
EmailMeNow domain audits on August 1, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture — not whether your login screen offers a YubiKey.
| Bank | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| JPMorgan Chase | chase.com | 79% | 75% | 15% | 94% | Good |
| Bank of America | bankofamerica.com | 70% | 50% | 45% | 92% | Good |
| U.S. Bank | usbank.com | 68% | 90% | 15% | 37% | Above Average |
| Wells Fargo | wellsfargo.com | 67% | 50% | 15% | 87% | Above Average |
| Capital One | capitalone.com | 58% | 60% | 15% | 45% | Average |
| Citibank | citi.com | 50% | 40% | 15% | 45% | Average |
Audit links: chase.com · bankofamerica.com · usbank.com · wellsfargo.com · capitalone.com · citi.com
Pattern: Strong websites do not equal strong MFA. Chase leads at 79% with 94% website — still 15% transport. Citi trails at 50% overall while MFA docs still center on SMS OTP.
Cybersquat / lookalike scan
DoH BEC-profile scans (registered-only) on key national brands:
| Brand | Checked | To review | BEC staging | Example threats |
|---|---|---|---|---|
chase.com | 118 | 96 | 2 | chase.io, chasen.com |
bankofamerica.com | 242 | 175 | 1 | bankofamer1ca.com (MX) |
wellsfargo.com | 194 | 119 | 2 | weilsfargo.com, wellsfargo-secure.com |
National bank brands sit in a dense lookalike space. SMS MFA fails harder when customers can also be phished from wellsfargo-secure.com-style hosts.
What customers should do
- Prefer FIDO / security keys where offered (Bank of America USB security key today; ask other banks for FIDO2).
- Turn on passkeys at Chase, Wells Fargo, U.S. Bank, and Capital One when available — phishing-resistant login beats password + SMS.
- Do not treat SMS as “good MFA.” Use it only if the bank offers nothing stronger; lock your mobile number (carrier PIN / port freeze).
- Ask product teams for Google Authenticator / Proton Pass TOTP — absence is a product choice, not a physics limit.
Recommended MFA tools
When a bank documents YubiKey / FIDO or you need open TOTP / passkeys elsewhere (email, password managers), these are practical options:
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.
Related trackers
- IBM Cost of a Data Breach Report 2026
- MFA support directory — YubiKey, authenticator apps & passkeys
- Texas banks MFA — SMS Secure Access Codes vs YubiKey
- State bank listicles (MFA tables included): e.g. California · Florida · New York — or filter the directory by Region
- Major U.S. banks email security
- Top Texas banks email security
- FaceTime bank scam
- Surfside Beach municipal BEC
Sources: Bank of America USB Security Key; Chase How we protect you; Wells Fargo 2FA / Passkeys; U.S. Bank two-step verification / Passkeys; Capital One Mobile App Verification / Passkeys. Independent EmailMeNow domain audits and cybersquat scans August 1, 2026. MFA grades reflect public documentation, not a private account enumeration. Domain scores: audit.emailmenow.com only.