Two-factor authentication.
In plain English
Two-factor authentication, often shortened to 2FA, means logging in takes two separate proofs instead of one. The first is something you know, your password. The second is something you have or are, like a code from an app, a text message, or your fingerprint. Even if a scammer steals your password, they still cannot get in without that second proof. Most banks and email providers let you turn it on in the security settings.
01Why it matters
Passwords get leaked in data breaches all the time, and 2FA is the single biggest thing that keeps a leaked password from becoming a drained account. It turns a stolen password into a useless one.
02The math, step by step
You enter your bank password, and the bank texts a six-digit code to your phone. You type the code in to finish logging in. A scammer who bought your password in a breach cannot get past this step because the code goes to your phone, not theirs. An app-based code is safer than a texted code, because texts can be intercepted by a SIM-swap attack.
03What this is NOT
Two-factor authentication is not the same as having a long, complex password. A strong password is still just one factor. 2FA adds a separate second proof, so it protects you even after the password itself is exposed.
04Receipts
Every figure on this page is sourced to a primary document. Tap to open the original.
Plain-English answers from our glossary. Receipts included. Never advice.
Educational tool. Answers come only from ClearMoneySchool's published glossary and are not advice. Why we never give advice