Several major German banks including Deutsche Bank and Commerzbank still require SMS-based two-factor authentication for login, but many are moving towards app-based authenticators and hardware tokens for improved security.
Overview of SMS-based 2FA in Germany
Two-factor authentication (2FA) has become a standard security measure in the German banking sector to safeguard customer accounts. Among the various 2FA methods, SMS-based verification remains widely used for login confirmation. This method involves sending a one-time password (OTP) via SMS to the user's registered mobile number.
Despite the convenience and ubiquity of SMS, its security limitations have prompted German banks to explore and adopt more advanced methods. However, SMS 2FA remains a default or fallback option in many institutions due to regulatory requirements and customer familiarity.
Under the EU's Payment Services Directive 2 (PSD2), banks must implement strong customer authentication (SCA), but SMS remains an approved 2FA channel despite its known vulnerabilities.
Banks using SMS 2FA for login
While many German banks are transitioning away from SMS 2FA, several prominent institutions still require it for login verification, particularly for online banking portals and mobile apps. Below is an overview of key players:
| Bank | SMS 2FA for Login | Alternative 2FA Options |
|---|---|---|
| Deutsche Bank | Yes | Mobile app, hardware token |
| Commerzbank | Yes | Commerzbank app, push notifications |
| Sparkassen (regional) | Yes, varies by branch | App-based TAN, chipTAN |
| Volksbanken Raiffeisenbanken | Partial, depends on region | App, chipTAN |
| ING Germany | No | App code, biometric login |
| N26 | No | App push notification |
Deutsche Bank and Commerzbank prominently use SMS OTPs for login verification but complement this with mobile app authenticators or hardware tokens. Many regional banks, including Sparkassen and Volksbanken, still rely on SMS 2FA, though some local branches provide app or chipTAN alternatives.
Check with your specific bank branch or online portal settings as SMS 2FA policies can vary regionally and by product type.
Security implications of SMS 2FA
While SMS-based two-factor authentication improves security over passwords alone, it carries notable risks, particularly in Germany where SIM swapping attacks have increased in recent years.
- SIM swapping: Attackers impersonate customers to mobile carriers to hijack phone numbers and intercept OTPs.
- SMS interception: Vulnerabilities in the SS7 protocol allow attackers to intercept SMS messages.
- Phishing: Users may be tricked into revealing OTPs via fraudulent websites or calls.
Relying solely on SMS 2FA can give a false sense of security; it is essential to combine it with additional security layers or migrate to more secure methods.
Financial regulators and cybersecurity experts recommend limiting SMS 2FA usage where possible, especially for login flows, favoring app-based authentication or hardware tokens that generate codes offline.
Alternatives to SMS 2FA
German banks have been increasingly rolling out alternative 2FA methods to replace or supplement SMS-based authentication:
Mobile app authenticators
Apps like Deutsche Bank's Mobile TAN or Commerzbank's pushTAN generate or push OTPs securely without relying on SMS.
Hardware tokens
Physical devices generate one-time codes offline, immune to network attacks.
Biometric login
Fingerprint or facial recognition enabled via banking apps enhance user convenience and security.
These methods conform with PSD2 regulations and reduce the attack surface compared to SMS-based verification.
Future trends in banking authentication
The German banking sector is actively evolving to strengthen authentication security and customer convenience. Key trends include:
- Phasing out SMS 2FA: Many banks plan to reduce SMS reliance within the next 2-3 years.
- Increased biometric adoption: Smartphone biometric sensors are becoming standard for secure app access.
- Regulatory push: PSD2 updates and GDPR encourage stronger, privacy-focused authentication methods.
- Open banking APIs: New secure communication protocols facilitate token-based authentication.
While SMS 2FA remains prevalent, customers should proactively switch to stronger methods when available to minimize security risks.
Frequently asked questions
Why do some German banks still use SMS-based 2FA?
What are the main security risks of SMS-based 2FA for banking?
Which major German banks currently require SMS 2FA for login?
Are there alternatives to SMS 2FA offered by German banks?
Will SMS-based 2FA disappear completely from German banking soon?
How does SMS 2FA compare to app-based authenticators in Germany?
Can SMSVerifier help with SMS 2FA for German bank accounts?
Ready to receive your first SMS verification code?
Register in 30 seconds — no card required, pay-as-you-go from $0.20 per SMS with SMSVerifier.
Get a German virtual number