Back to news
Cybersecurity Alert
August 1, 2026 by EmailMeNow IT Consulting

Texas Banks Still Fail MFA — SMS Secure Access Codes Dominate Over YubiKey and Authenticator Apps

Public MFA docs for Frost, Comerica, Southside, Broadway, TRB, Prosperity, Texas Capital, and Independent Financial show SMS / voice codes still dominate. None advertise Google Authenticator / Proton Pass TOTP or consumer YubiKey. Domain audits (ideal 100%): texascapitalbank.com 84%; comerica.com 37% — none at 100%.

Source: EmailMeNow research

NewsBanksMFAYubiKeyAuthenticator AppsSIM SwapTexasFinancial ServicesCybersecurity
Texas map with MFA strength markers for regional banks

Phone-number multi-factor authentication is still the default at most Texas banks — and under our grading rules that is a fail. SIM-swap and SS7 / number-port abuse have a long public history of stealing SMS one-time codes. We checked whether regional online banking advertises YubiKey-class FIDO security keys or standard authenticator-app TOTP (Google Authenticator, Proton Pass, and peers). The pattern matches the nationals: Secure Access Codes by text/voice, app biometrics, and proprietary business tokens — not open TOTP and not consumer hardware keys.

Domain security is a separate control plane. Fresh audit.emailmenow.com scores on August 1, 2026 show none of these banks at the 100% ideal.

Industry cost context (IBM / Ponemon 2026): financial services breaches averaged USD 6.29M, with AI-driven attacks disproportionately hitting finance and energy. See IBM Cost of a Data Breach 2026.

For the six largest national banks, see the companion scorecard: National banks MFA — SMS vs YubiKey & authenticator apps.

Texas map with MFA strength markers for regional banks

How we graded MFA

Public consumer (and clearly labeled business) documentation only — not a logged-in mystery shop of every account type. Methods change; re-check your bank before you rely on this table.

GradeMeaning
FailDocumented consumer second factor is primarily SMS / voice / phone OTP (SIM-swap class)
PartialBetter than SMS alone (bank app push, proprietary soft token, passkeys) but no standard TOTP and no YubiKey/FIDO key
Pass (TOTP)Self-serve Google Authenticator / Proton Pass-style OATH TOTP for login
StrongConsumer FIDO2 / FIDO security key (YubiKey-class) for sign-in or high-risk steps

Phone MFA = Fail in this scorecard even when the bank also offers biometrics or passkeys. Passkeys help phishing resistance for login; they do not erase an SMS-only second-factor path when that is what the bank documents for “2-step verification.”

Texas MFA scoreboard: SMS fail, soft-token partial, hardware key strong

Texas banks — MFA support

BankYubiKey / FIDOAuthenticator TOTPStronger optionPhone OTPMFA grade
Texas Regional Bank
trb.bank
NoNoOptional Symantec VIP; app biometricsYes — SAC text/voice (Info Hub)Fail
Frost Bank
frostbank.com
NoNoApp biometricsNot marketed as authenticator/YubiKeyFail
Comerica
comerica.com
NoNoMFA OTP guidanceYes — OTP / textFail
Southside Bank
southside.com
NoNoApp biometricsText verification codesFail
Broadway Bank
broadway.bank
No (consumer)NoBusiness iBIZ Token; wealth text/voice 2FAYes (wealth)Fail (SMS) / Partial (biz token)
Prosperity Bank
prosperitybankusa.com
NoNoBusiness Prosperity Bank TokenNot TOTP/YubiKeyFail (consumer) / Partial (treasury)
Texas Capital Bank
texascapitalbank.com
No consumerNoRSA SecurID for some usersNot retail TOTPPartial (token programs)
Independent Financial
ifinancial.com
No public docsNoAssumed phone/OTP classFail

Takeaway: Texas regional banks closely track the national pattern: SMS / voice Secure Access Codes, biometrics in the app, and proprietary business tokens — not open authenticator apps and not YubiKeys. TRB is explicit: MFA settings manage SAC delivery contacts (text/voice), not a QR for Proton Pass.

SMS bank code marked weak beside hardware key — same failure mode as national banks

Why SMS MFA fails this scorecard

RiskWhy phone OTP loses
SIM swap / port-outAttacker takes the number → receives the bank’s SMS code
SS7 / SMS interceptionCodes travel over carrier messaging, not an end-to-end authenticator
Social engineeringVictims are tricked into reading codes to “bank fraud” callers
Shared recoveryPhone number often resets email + bank + password manager

CISA and industry guidance treat phishing-resistant MFA (FIDO/WebAuthn security keys and well-implemented passkeys) as the top tier. Authenticator-app TOTP is the practical middle for apps that refuse hardware keys. SMS is the bottom tier that still gets labeled “MFA.”

Independent cybersecurity audits

EmailMeNow domain audits on August 1, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture — not whether your login screen offers a YubiKey.

BankDomainOverallIdentityTransportWebsiteRisk
Texas Capital Banktexascapitalbank.com84%90%15%90%Good
Southside Banksouthside.com83%90%45%84%Good
Frost Bankfrostbank.com68%50%15%92%Above Average
Broadway Bankbroadway.bank64%65%80%45%Above Average
Independent Financialifinancial.com64%40%15%92%Above Average
Prosperity Bankprosperitybankusa.com59%65%45%37%Average
Texas Regional Banktrb.bank58%40%45%65%Average
Comericacomerica.com37%10%15%40%Weak

Audit links: texascapitalbank.com · southside.com · frostbank.com · broadway.bank · ifinancial.com · prosperitybankusa.com · trb.bank · comerica.com

Pattern: Strong websites do not equal strong MFA. Texas Capital (84%) and Southside (83%) lead domain scores while MFA docs still skip open TOTP/YubiKey. Comerica is the weak outlier at 37% overall / 10% identity.

Website stack note

Passive website-tech probes on August 1, 2026 across this Texas set:

DomainFinding
texascapitalbank.comDrupal major version behind (reports 10; current major referenced 11.4.4)

Other Texas bank marketing hosts in this set did not surface notable CMS/PHP/TLS aging bullets in the same pass.

Cybersquat / lookalike scan

DoH BEC-profile scans (registered-only) on key Texas brands:

BrandCheckedTo reviewBEC stagingExample threats
frostbank.com180302frosfbank.com, frosthank.com
trb.bank87142tfb.bank, trb.tech
texascapitalbank.com29050TLD swaps only
comerica.com164500Many registered near-misses

Regional brands still sit in a lookalike space. SMS MFA fails harder when customers can also be phished from typo or TLD-swap hosts.

What customers should do

  1. Do not treat SMS / SAC as “good MFA.” Use it only if the bank offers nothing stronger; lock your mobile number (carrier PIN / port freeze).
  2. Business / treasury users: enroll the bank’s soft token (VIP, RSA, Prosperity Token, iBIZ, DIGIPASS) instead of SMS for wires/ACH.
  3. Ask product teams for Google Authenticator / Proton Pass TOTP and consumer FIDO / YubiKey — absence is a product choice, not a physics limit.
  4. Compare with nationals: Bank of America already documents a USB security key path; Texas banks can match that bar.

When a bank documents YubiKey / FIDO or you need open TOTP / passkeys elsewhere (email, password managers), these are practical options:

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.


Sources: Texas Regional Bank Info Hub; Broadway wealth 2FA PDF. Independent EmailMeNow domain audits, website-tech probes, and cybersquat scans August 1, 2026. MFA grades reflect public documentation, not a private account enumeration. Domain scores: audit.emailmenow.com only.