Advanced-2FA-Voice

Which banks in Germany still require SMS-based two-factor authentication for login?

July 30, 2026 · 5 min read · 8 views
Several major German banks including Deutsche Bank and Commerzbank still require SMS-based two-factor authentication for login, but many are moving towards app-based authenticators and hardware tokens for improved security.

Overview of SMS-based 2FA in Germany

Two-factor authentication (2FA) has become a standard security measure in the German banking sector to safeguard customer accounts. Among the various 2FA methods, SMS-based verification remains widely used for login confirmation. This method involves sending a one-time password (OTP) via SMS to the user's registered mobile number.

Despite the convenience and ubiquity of SMS, its security limitations have prompted German banks to explore and adopt more advanced methods. However, SMS 2FA remains a default or fallback option in many institutions due to regulatory requirements and customer familiarity.

Important context.

Under the EU's Payment Services Directive 2 (PSD2), banks must implement strong customer authentication (SCA), but SMS remains an approved 2FA channel despite its known vulnerabilities.

Banks using SMS 2FA for login

While many German banks are transitioning away from SMS 2FA, several prominent institutions still require it for login verification, particularly for online banking portals and mobile apps. Below is an overview of key players:

BankSMS 2FA for LoginAlternative 2FA Options
Deutsche BankYesMobile app, hardware token
CommerzbankYesCommerzbank app, push notifications
Sparkassen (regional)Yes, varies by branchApp-based TAN, chipTAN
Volksbanken RaiffeisenbankenPartial, depends on regionApp, chipTAN
ING GermanyNoApp code, biometric login
N26NoApp push notification

Deutsche Bank and Commerzbank prominently use SMS OTPs for login verification but complement this with mobile app authenticators or hardware tokens. Many regional banks, including Sparkassen and Volksbanken, still rely on SMS 2FA, though some local branches provide app or chipTAN alternatives.

Pro tip.

Check with your specific bank branch or online portal settings as SMS 2FA policies can vary regionally and by product type.

Security implications of SMS 2FA

While SMS-based two-factor authentication improves security over passwords alone, it carries notable risks, particularly in Germany where SIM swapping attacks have increased in recent years.

  • SIM swapping: Attackers impersonate customers to mobile carriers to hijack phone numbers and intercept OTPs.
  • SMS interception: Vulnerabilities in the SS7 protocol allow attackers to intercept SMS messages.
  • Phishing: Users may be tricked into revealing OTPs via fraudulent websites or calls.
Common pitfall.

Relying solely on SMS 2FA can give a false sense of security; it is essential to combine it with additional security layers or migrate to more secure methods.

Financial regulators and cybersecurity experts recommend limiting SMS 2FA usage where possible, especially for login flows, favoring app-based authentication or hardware tokens that generate codes offline.

Alternatives to SMS 2FA

German banks have been increasingly rolling out alternative 2FA methods to replace or supplement SMS-based authentication:

📱

Mobile app authenticators

Apps like Deutsche Bank's Mobile TAN or Commerzbank's pushTAN generate or push OTPs securely without relying on SMS.

🔑

Hardware tokens

Physical devices generate one-time codes offline, immune to network attacks.

🆔

Biometric login

Fingerprint or facial recognition enabled via banking apps enhance user convenience and security.

These methods conform with PSD2 regulations and reduce the attack surface compared to SMS-based verification.

"App-based authenticators and hardware tokens represent the gold standard for secure banking 2FA in Germany."

The German banking sector is actively evolving to strengthen authentication security and customer convenience. Key trends include:

  • Phasing out SMS 2FA: Many banks plan to reduce SMS reliance within the next 2-3 years.
  • Increased biometric adoption: Smartphone biometric sensors are becoming standard for secure app access.
  • Regulatory push: PSD2 updates and GDPR encourage stronger, privacy-focused authentication methods.
  • Open banking APIs: New secure communication protocols facilitate token-based authentication.
  • 2020-2022 Banks introduce mobile app TANs and push notifications to complement SMS 2FA.
  • 2023-2024 Gradual deprecation of SMS 2FA in favor of biometrics and hardware tokens.
  • 2025 and beyond Universal adoption of app-based and biometric authentication as defaults.
  • Important context.

    While SMS 2FA remains prevalent, customers should proactively switch to stronger methods when available to minimize security risks.

    Frequently asked questions

    Why do some German banks still use SMS-based 2FA?
    Many German banks continue using SMS-based two-factor authentication because it is widely accessible and familiar to customers, despite known security weaknesses.
    What are the main security risks of SMS-based 2FA for banking?
    SMS-based 2FA is vulnerable to SIM swapping, interception, and phishing attacks, which can expose customer accounts to unauthorized access.
    Which major German banks currently require SMS 2FA for login?
    Banks like Deutsche Bank, Commerzbank, and some regional Sparkassen branches still use SMS-based 2FA for login verification, though many are transitioning to app-based methods.
    Are there alternatives to SMS 2FA offered by German banks?
    Yes, many banks now offer app-based authenticators, hardware tokens, or biometric login options as more secure alternatives to SMS 2FA.
    Will SMS-based 2FA disappear completely from German banking soon?
    While the trend favors stronger authentication methods, SMS 2FA will likely remain for some customers or legacy systems for the near future due to regulatory and technical constraints.
    How does SMS 2FA compare to app-based authenticators in Germany?
    App-based authenticators provide better security by generating offline codes and avoiding network vulnerabilities inherent to SMS delivery.
    Can SMSVerifier help with SMS 2FA for German bank accounts?
    SMSVerifier provides virtual phone numbers for SMS verification but does not support banking login processes due to legal and security restrictions.

    Ready to receive your first SMS verification code?

    Register in 30 seconds — no card required, pay-as-you-go from $0.20 per SMS with SMSVerifier.

    Get a German virtual number
    Tags: germany 2fa sms banking security
    Browse Services A-Z
    A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #
    View all services →
    From Our Blog
    Browse all articles →