Legit or Scam
Protection & response

Two-Factor Authentication (2FA)

Updated June 1, 2026Also called: 2fa, mfa, multi-factor authentication

A second login step beyond your password, blocking most account takeovers even if a password leaks.

Two-factor authentication requires something in addition to your password — a code from an app, a security key, a prompt. Even if scammers harvest your password, they usually cannot log in without the second factor.

Prefer app-based or hardware 2FA over SMS codes, which can be intercepted, and never share a 2FA code with anyone who contacts you.

Red flags

  • Anyone asking you to read back a 2FA/verification code
  • Unexpected login prompts you didn't initiate

Frequently asked questions

Should I ever share a 2FA code?

Never. A legitimate company will not call or message asking for your one-time code. Anyone requesting it is trying to break into your account.

Related terms

Spot it before it costs you

Legit or Scam turns terms like this into instinct. Drop into real-world offers, recruiter DMs, and texts, and see how many you can call correctly.

Play Legit or Scam

Educational content only — not legal, financial, or security advice. Scenarios and company names are illustrative.