A whistleblower provides nonpublic data revealing that 1M+ 2FA SMS messages from June 2023 passed via Fink Telecom, a small Swiss company linked to spy agencies
Every day, millions of people sign in to their email, banking app or social media accounts with both their password and a one-time login code they receive by text message.
Context & Ripple Effects
The report adds a carrier-routing layer to a long-running weakness in SMS-based authentication. Earlier coverage showed that SMS messages could be rerouted cheaply enough to enable account takeovers, as in the Sakari text-rerouting incident.
It also follows cases in which verification codes were exposed through telecom-service failures, including the Twilio breach affecting Signal users. The new allegation matters because it shifts attention from a single breached provider to the opaque intermediaries that carry authentication traffic.
First-order effects
- Organizations sending one-time codes through routes involving Fink Telecom now have a concrete reason to review their messaging supply chain and the handling of authentication traffic.
- Fink Telecom faces heightened scrutiny over the reported routing data and the whistleblower's alleged links to spy agencies; SMS recipients cannot readily see which intermediary handled a code.
Second-order effects
- Identity and messaging vendors may face pressure from customers to disclose downstream routing partners, strengthen vendor due diligence, or offer non-SMS authentication paths.
- The finding reinforces the security case for moving sensitive account recovery and login flows away from SMS, especially where a code's transit path is hard for the sender to audit.
Third-order effects
- If carriers and intermediaries remain opaque, authentication security will increasingly be judged as a supply-chain governance problem, not simply a question of whether users enable 2FA.
- The pattern could accelerate a shift toward authentication methods that reduce reliance on telecom routing, while increasing demands for accountability over who processes identity-verification data.
The trend: SMS authentication is becoming a weaker trust anchor as attention moves from endpoint breaches to the hidden telecom supply chain behind verification codes.