Reddit's Breach via SMS Interception (Aug 2018): Why SMS MFA Isn't Enough
Retrospective: this article looks back at events from August 2018, written in 2026 with the benefit of hindsight.
On August 1, 2018, Reddit disclosed that an attacker had accessed some of its systems, including an old database backup with user data from 2007 and email digests from 2018. The most important detail was how the attacker got in.
How it happened
Reddit said the attacker compromised a few employee accounts at its cloud and source code hosting providers between June 14 and June 18, 2018. Those accounts were protected by SMS-based two-factor authentication. The attacker intercepted the SMS codes. Reddit said the main attack was via SMS intercept and called out that SMS-based authentication was "not nearly as secure as we would hope."
Why SMS is weak
SMS codes can be intercepted or redirected through:
- SIM swapping: convincing a mobile carrier to move a phone number to an attacker's SIM card.
- Weaknesses in the telephone signaling network (SS7).
- Phishing: users can be tricked into typing the code into a fake page.
SMS is still far better than no second factor, but it is the weakest common form of MFA.
Lessons for Microsoft 365 and cloud identity
- Move employees off SMS to the Microsoft Authenticator app with number matching as a minimum.
- Use phishing-resistant methods (FIDO2 security keys, passkeys, Windows Hello for Business) for administrators and access to critical systems.
- Protect accounts at third-party providers — cloud consoles, code hosting, DNS registrars — with the same strength as your own tenant.
- Old backups are still data. A 2007 backup should not have been reachable in 2018.
In hindsight
Reddit's candid disclosure helped shift industry guidance. NIST had already flagged SMS as a restricted authenticator, and today Microsoft's authentication methods policies let organizations disable SMS and voice entirely.
- How to Migrate Users From SMS to Authenticator App and FIDO2 MFA How-To & Hardening
- Detecting SMS MFA Interception: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Not All MFA Is Equal — The Case for Phishing-Resistant Methods CIO Briefings