Phone-number multi-factor authentication is still the default at most Texas banks — and under our grading rules that is a fail. SIM-swap and SS7 / number-port abuse have a long public history of stealing SMS one-time codes. We checked whether regional online banking advertises YubiKey-class FIDO security keys or standard authenticator-app TOTP (Google Authenticator, Proton Pass, and peers). The pattern matches the nationals: Secure Access Codes by text/voice, app biometrics, and proprietary business tokens — not open TOTP and not consumer hardware keys.
Domain security is a separate control plane. Fresh audit.emailmenow.com scores on August 1, 2026 show none of these banks at the 100% ideal.
Industry cost context (IBM / Ponemon 2026): financial services breaches averaged USD 6.29M, with AI-driven attacks disproportionately hitting finance and energy. See IBM Cost of a Data Breach 2026.
For the six largest national banks, see the companion scorecard: National banks MFA — SMS vs YubiKey & authenticator apps.

How we graded MFA
Public consumer (and clearly labeled business) documentation only — not a logged-in mystery shop of every account type. Methods change; re-check your bank before you rely on this table.
| Grade | Meaning |
|---|---|
| Fail | Documented consumer second factor is primarily SMS / voice / phone OTP (SIM-swap class) |
| Partial | Better than SMS alone (bank app push, proprietary soft token, passkeys) but no standard TOTP and no YubiKey/FIDO key |
| Pass (TOTP) | Self-serve Google Authenticator / Proton Pass-style OATH TOTP for login |
| Strong | Consumer FIDO2 / FIDO security key (YubiKey-class) for sign-in or high-risk steps |
Phone MFA = Fail in this scorecard even when the bank also offers biometrics or passkeys. Passkeys help phishing resistance for login; they do not erase an SMS-only second-factor path when that is what the bank documents for “2-step verification.”

Texas banks — MFA support
| Bank | YubiKey / FIDO | Authenticator TOTP | Stronger option | Phone OTP | MFA grade |
|---|---|---|---|---|---|
Texas Regional Banktrb.bank | No | No | Optional Symantec VIP; app biometrics | Yes — SAC text/voice (Info Hub) | Fail |
Frost Bankfrostbank.com | No | No | App biometrics | Not marketed as authenticator/YubiKey | Fail |
Comericacomerica.com | No | No | MFA OTP guidance | Yes — OTP / text | Fail |
Southside Banksouthside.com | No | No | App biometrics | Text verification codes | Fail |
Broadway Bankbroadway.bank | No (consumer) | No | Business iBIZ Token; wealth text/voice 2FA | Yes (wealth) | Fail (SMS) / Partial (biz token) |
Prosperity Bankprosperitybankusa.com | No | No | Business Prosperity Bank Token | Not TOTP/YubiKey | Fail (consumer) / Partial (treasury) |
Texas Capital Banktexascapitalbank.com | No consumer | No | RSA SecurID for some users | Not retail TOTP | Partial (token programs) |
Independent Financialifinancial.com | No public docs | No | — | Assumed phone/OTP class | Fail |
Takeaway: Texas regional banks closely track the national pattern: SMS / voice Secure Access Codes, biometrics in the app, and proprietary business tokens — not open authenticator apps and not YubiKeys. TRB is explicit: MFA settings manage SAC delivery contacts (text/voice), not a QR for Proton Pass.

Why SMS MFA fails this scorecard
| Risk | Why phone OTP loses |
|---|---|
| SIM swap / port-out | Attacker takes the number → receives the bank’s SMS code |
| SS7 / SMS interception | Codes travel over carrier messaging, not an end-to-end authenticator |
| Social engineering | Victims are tricked into reading codes to “bank fraud” callers |
| Shared recovery | Phone number often resets email + bank + password manager |
CISA and industry guidance treat phishing-resistant MFA (FIDO/WebAuthn security keys and well-implemented passkeys) as the top tier. Authenticator-app TOTP is the practical middle for apps that refuse hardware keys. SMS is the bottom tier that still gets labeled “MFA.”
Independent cybersecurity audits
EmailMeNow domain audits on August 1, 2026. 100% is the ideal overall score — none of these reach it. Scores measure public identity / transport / website posture — not whether your login screen offers a YubiKey.
| Bank | Domain | Overall | Identity | Transport | Website | Risk |
|---|---|---|---|---|---|---|
| Texas Capital Bank | texascapitalbank.com | 84% | 90% | 15% | 90% | Good |
| Southside Bank | southside.com | 83% | 90% | 45% | 84% | Good |
| Frost Bank | frostbank.com | 68% | 50% | 15% | 92% | Above Average |
| Broadway Bank | broadway.bank | 64% | 65% | 80% | 45% | Above Average |
| Independent Financial | ifinancial.com | 64% | 40% | 15% | 92% | Above Average |
| Prosperity Bank | prosperitybankusa.com | 59% | 65% | 45% | 37% | Average |
| Texas Regional Bank | trb.bank | 58% | 40% | 45% | 65% | Average |
| Comerica | comerica.com | 37% | 10% | 15% | 40% | Weak |
Audit links: texascapitalbank.com · southside.com · frostbank.com · broadway.bank · ifinancial.com · prosperitybankusa.com · trb.bank · comerica.com
Pattern: Strong websites do not equal strong MFA. Texas Capital (84%) and Southside (83%) lead domain scores while MFA docs still skip open TOTP/YubiKey. Comerica is the weak outlier at 37% overall / 10% identity.
Website stack note
Passive website-tech probes on August 1, 2026 across this Texas set:
| Domain | Finding |
|---|---|
texascapitalbank.com | Drupal major version behind (reports 10; current major referenced 11.4.4) |
Other Texas bank marketing hosts in this set did not surface notable CMS/PHP/TLS aging bullets in the same pass.
Cybersquat / lookalike scan
DoH BEC-profile scans (registered-only) on key Texas brands:
| Brand | Checked | To review | BEC staging | Example threats |
|---|---|---|---|---|
frostbank.com | 180 | 30 | 2 | frosfbank.com, frosthank.com |
trb.bank | 87 | 14 | 2 | tfb.bank, trb.tech |
texascapitalbank.com | 290 | 5 | 0 | TLD swaps only |
comerica.com | 164 | 50 | 0 | Many registered near-misses |
Regional brands still sit in a lookalike space. SMS MFA fails harder when customers can also be phished from typo or TLD-swap hosts.
What customers should do
- Do not treat SMS / SAC as “good MFA.” Use it only if the bank offers nothing stronger; lock your mobile number (carrier PIN / port freeze).
- Business / treasury users: enroll the bank’s soft token (VIP, RSA, Prosperity Token, iBIZ, DIGIPASS) instead of SMS for wires/ACH.
- Ask product teams for Google Authenticator / Proton Pass TOTP and consumer FIDO / YubiKey — absence is a product choice, not a physics limit.
- Compare with nationals: Bank of America already documents a USB security key path; Texas banks can match that bar.
Recommended MFA tools
When a bank documents YubiKey / FIDO or you need open TOTP / passkeys elsewhere (email, password managers), these are practical options:
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.
Related trackers
- IBM Cost of a Data Breach Report 2026
- MFA support directory — YubiKey, authenticator apps & passkeys
- National banks MFA — SMS vs YubiKey & authenticator apps
- Top Texas banks email security (includes MFA table)
- Major U.S. banks email security
- TMHP IAMOnline MFA (Texas Medicaid)
- FaceTime bank scam
- Surfside Beach municipal BEC
Sources: Texas Regional Bank Info Hub; Broadway wealth 2FA PDF. Independent EmailMeNow domain audits, website-tech probes, and cybersquat scans August 1, 2026. MFA grades reflect public documentation, not a private account enumeration. Domain scores: audit.emailmenow.com only.