Instagram to Introduce Non-SMS Two-Factor Authentication to Prevent SIM Hacking - MacRumors
Skip to Content

Instagram to Introduce Non-SMS Two-Factor Authentication to Prevent SIM Hacking

by

Instagram is planning to introduce a new two-factor authentication method that will not require a user's phone number and will instead work with authentication apps like Google Authenticator, reports TechCrunch.

Authentication apps are a safer two-factor option than the phone number method, which can be bypassed through SIM hacking, as outlined earlier today by VICE's Motherboard.

instagramtwofactortc

Image via TechCrunch

SIM hacking involves hijacking a person's phone number by manipulating cellular service support staff and claiming a SIM card has been lost.

Creating a new SIM associated with the phone number allows it to be stolen, and if that phone number is associated with a social networking account, as it would be with Instagram's current two-factor authentication method, the results can be devastating.

In Motherboard's article, for example, SIM hacking is used to steal Instagram accounts, which can be lucrative when highly desired usernames are poached.

Instagram is especially vulnerable to this kind of attack because right now, when you turn on Instagram's two-factor authentication, account codes and password reset requests are sent via your phone number.

Instagram has already been testing the new two-factor authentication method, with screenshots and details baked into the code for the Instagram Android app. This code was discovered by a TechCrunch tipster, who also shared screenshots.

An Instagram spokesperson confirmed the screenshots are legitimate and said Instagram is "continuing to improve the security of Instagram accounts, including strengthening 2-factor authentication."

It is not yet clear when Instagram plans to roll out the new two-factor authentication method, but it could come soon as it appears to be nearly finished based on the screenshots.

Top Rated Comments

102 months ago
I’d rather an option for all services to have no two factor authentication. It’s a real bother for those who take the time to use a password manager to generate strong, unique passwords. Then store said passwords in an encrypted vault protected by one strong password.

At least create a standard for two factor authentication. So our password managers can automatically receive and fill the code.

As it stands. Two factor just increases login time.
I find it hilarious when im logging into iCloud on my Mac and it asks me for two factor, and then sends the code to the freakin laptop cause it’s already authorized. I would love to see a standardized two factor login.
Score: 4 Votes (Like | Disagree)
hank moody Avatar
102 months ago
Please, just stop promoting google auth.
There are plenty of BETTER and open source apps out there to talk about.
Score: 3 Votes (Like | Disagree)
102 months ago
I’d rather an option for all services to have no two factor authentication. It’s a real bother for those who take the time to use a password manager to generate strong, unique passwords. Then store said passwords in an encrypted vault protected by one strong password.

At least create a standard for two factor authentication. So our password managers can automatically receive and fill the code.

As it stands. Two factor just increases login time.
1Password handles TFA with One-Time Passcodes if you use their app.
Score: 1 Votes (Like | Disagree)
102 months ago
These apps are just distractions to me. They are generally fun to scroll and get a chuckle or see something interesting. But if they are unable to secure their systems, and instead start to make me have to download another app to use their app, and click multiple times to get into an app that is at best a fun diversion, then I will just delete my account and the app and move on.
Score: 1 Votes (Like | Disagree)

Popular Stories

Instagram Feature 2

PSA: Instagram Encrypted Messaging Ends on Friday, May 8

Tuesday May 5, 2026 8:24 am PDT by
Instagram will remove end-to-end encryption for direct messages between users from May 8, 2026. When the date comes around, Meta will potentially be able to see the contents of all messages between users on the social media platform. Encrypting messages has been an optional feature in Instagram since 2023, but in March of this year the social media platform quietly updated a help page to say ...
Instagram Feature 1

Warning: Instagram DMs Lose End-to-End Encryption Starting Today

Friday May 8, 2026 12:37 pm PDT by
As of today, end-to-end encryption for Instagram direct messages is no longer available. DMs that you send to people on Instagram will no longer feature full encryption, and your conversations are not protected from Meta. Meta can potentially see what's in messages shared between users on Instagram, and that information can be shared with law enforcement agencies worldwide. End-to-end...
Apple Event Logo

Apple's Next Era Begins September 1

Thursday May 7, 2026 10:36 am PDT by
Apple recently announced that Tim Cook will be stepping down as CEO later this year, after 15 years of leading the company. Effective September 1, Apple's hardware engineering chief John Ternus will become the company's next CEO, while Cook will become executive chairman of Apple's board of directors. In his new role, Apple said Cook will assist with "certain aspects" of the company,...