Definition
Two-Factor Authentication (2FA)
Requiring a second proof of identity beyond your password, so a stolen password alone is not enough to log in.
Two-factor authentication adds a second factor — an app-generated code, a hardware key, or a biometric — on top of your password. The strongest forms use a hardware security key or an authenticator app rather than SMS, which can be intercepted or SIM-swapped.
Why it matters: most account takeovers start with a reused or leaked password. A second factor blocks the vast majority of them. Prefer hardware keys or app codes over text messages.
Related terms
Password Manager · Risk signal Model · Impersonation scam (Impersonation Scams)