National Institute of Standards and Technology has stated that SMS is insecure, and is no longer suitable as a strong authentication mechanism. SMS Messages are not protected from the wrong eyes seeing them, and there is no assurance that they will actually go to the intended recipient. In the worst of cases, misplaced trust saw it leveraged for access to highly-targeted intellectual property, “secure” networks, and even some credit card issuers and financial institutions. Alternative alternatives exist, and your application can be protected by run-time self-protection and device-binding technologies.”]
Source: https://www.bankinfosecurity.com/blogs/i-hope-that-no-one-gets-my-sms-message-in-bottle-p-2206

