You probably never think about your phone’s network settings unless you’ve run into some kind of problem. But 2G is one of those settings that you absolutely should take the time to disable.
It’s a dated technology, sure, but your phone still supports it, and that’s a problem because scammers can exploit less secure 2G networks to send fraud texts without ever going through your carrier’s network.
2G has a serious security problem
The one-way trust problem
2G hasn’t been relevant for years, to the point where most of us don’t even think about it anymore. But it’s still available, and more importantly, your Android phone can connect to it automatically if you’re ever in a remote area where 2G is the only option. Carriers need it as a fallback option, and the infrastructure is already there, so there’s little incentive to shut it off entirely.
But the problem with 2G is that it only authenticates in one direction. Your phone has to prove itself to the tower, but the tower doesn’t have to prove its authenticity. That’s not the case with 3G, 4G, or 5G, and it’s exactly what makes 2G a liability. A hacker could set up a fake tower, and your phone would connect to it without verifying anything. In fact, this type of attack is common enough to have a name: SMS Blaster fraud. Google even wrote about it on its security blog. So yes, the risk is very real.
An SMS Blaster is essentially a portable, fake cell tower, and it doesn’t take much skill to run one. Attackers typically plant one of these near a crowded area and have it broadcast signals that trick nearby phones to downgrade to 2G. And since 2G is active by default on most Android phones, they might connect to the fake cell tower thinking it’s giving the strongest signals.
From there, attackers lean on that one-way authentication problem I talked about. Since your phone never verifies the tower, and 2G lets connections run with little to no encryption, they get a clean man-in-the-middle position. They can now push SMS messages directly onto your phone, and this is no ordinary spam.
Since these texts don’t route through your carrier’s network, none of the anti-fraud or anti-spam filtering that would normally catch such phishing texts ever come into play. Attackers also have full freedom to spoof the sender ID, so the messages can look like they’re coming straight from your bank, insurance provider, a delivery service, or any other legitimate business.
Disabling 2G is an easy win
You aren’t giving up much
What makes this worse is that these SMS Blaster devices are easy to get. A hacker could buy one, carry it in a backpack or a car, and drive through a busy neighborhood to trick nearby phones. Google even mentions that the return on investment of these devices can be high, and these scams have been reported in France, Vietnam, Norway, Thailand, and several other countries.
This fraud might sound scary, but stopping it is as simple as turning off a toggle. On my Galaxy S26, I went to Settings > Connections > Mobile networks and disabled Allow 2G service toggle. On Pixels, it’s under Network & internet > SIMs > Your SIM.
Once you disable 2G, you’re basically immune to these attacks. There’s no real trade off either. Unless you’re traveling to a place where 2G is the only option, you’re probably not going to miss it much. Most cities and rural areas typically have better signals, so 2G is not necessary.
Google is already doing its bit to protect you
Your Android is smarter than you think
To be fair, Google isn’t sitting on this problem. Your Android phone already has a few features working to protect you from this kind of fraud. The first is Advanced Protection, which was introduced in Android 16. It blocks all unsecured networks outright, including 2G. So if you have this feature enabled, you don’t need to worry about disabling 2G since it’s already blocked. You can still use 2G for emergency calls, which is nice.
Google is also pushing carriers to require RCS for business messaging. Since RCS chats are encrypted and require verification, it’s a solid indication of where a text is actually coming from.
Then there are the security features that your Android phone has had for years. For instance, Safe Browsing automatically flags risky sites, sketchy downloads, and even extensions before you open them. Play Protect scans every app you install, even if you haven’t downloaded it from the Play Store. As long as you haven’t disabled these important security features, you have enough protection even with 2G on.
Finally, with Android 17, Google is letting carriers disable 2G by default. Google calls this “zero-click” solution, which basically means the solution doesn’t depend on the user knowing about all of this and disabling 2G manually.