A second login step beyond your password, blocking most account takeovers even if a password leaks.
Two-factor authentication requires something in addition to your password — a code from an app, a security key, a prompt. Even if scammers harvest your password, they usually cannot log in without the second factor.
Prefer app-based or hardware 2FA over SMS codes, which can be intercepted, and never share a 2FA code with anyone who contacts you.
Red flags
- Anyone asking you to read back a 2FA/verification code
- Unexpected login prompts you didn't initiate
Frequently asked questions
Should I ever share a 2FA code?
Never. A legitimate company will not call or message asking for your one-time code. Anyone requesting it is trying to break into your account.