Turn On Two-Factor Authentication — the 20-Minute Job That Stops Most Account Theft

Updated September 1, 2026

A padlock resting on a laptop keyboard

Most account theft is not hacking in any dramatic sense. Someone buys a list of passwords leaked in an old breach, tries yours against your email login, and it works — because it is the same password you used on a shopping site in 2019. Two-factor authentication is the setting that makes a stolen password worthless on its own: after the password, the service asks for a code or an approval that only something you physically hold can produce.

It is the highest-value twenty minutes of security work available to an ordinary person. The order you do it in matters more than most people realise, so start there.

Do email first — the order matters

This is the part people get wrong. They protect the bank and leave email open. But every password reset in your life flows through your inbox. Protect the bank alone, and someone sitting in your email simply clicks “forgot password” at the bank and catches the reset link on the way in. Protect the email and you protect everything downstream of it.

So the order is: email, then your password manager, then banking and payments, then anything with a card saved — Amazon, PayPal, the app stores — then social media. Social comes last not because it doesn't matter, but because the real damage runs through mail and money. If your inbox has already been taken over, stop reading and deal with that now — the first hour matters most — then come back and lock the doors properly.

Not all second factors are equal

  1. Hardware key (YubiKey and similar) — the strongest option, and effectively immune to phishing, because the key checks it is talking to the genuine site before it answers. Worth the modest cost for a business owner or anyone who moves real money.
  2. Authenticator app (Microsoft Authenticator, Google Authenticator, 2FAS, or the one built into your password manager) — the right default for nearly everyone. Free, works offline, and the codes are generated on the phone itself.
  3. Text message — much better than nothing, and the weakest of the three.

The reasoning is worth thirty seconds. Text codes beat nothing because the person who bought your leaked password almost never has your phone — even SMS stops bulk, automated account theft cold. The app beats text because your phone number is not really yours: it belongs to the carrier, and a criminal who talks a carrier rep into a SIM swap receives your texted codes on their handset while yours goes quiet. App codes never cross the phone network, so there is nothing in transit to steal. Use text codes only where nothing better is offered, and switch the day the account grows up.

Passkeys are where this is going

A passkey replaces the password and the code with one step. Your device stores a private key; you approve each sign-in with a fingerprint, your face or the device PIN; nothing is typed, and nothing works on a fake site, because a passkey will only answer the genuine one. This has stopped being a niche feature — the FIDO Alliance's State of Passkeys report, published in May 2026, counted roughly five billion passkeys in use worldwide, and 75% of the people it surveyed had enabled one on at least one account.

The practical advice is simple. When Google, Apple, Microsoft, Amazon or your bank offers to add a passkey, say yes. Keep an authenticator app registered on the same account as a fallback for now — passkeys are still young enough that recovery procedures vary from one service to the next.

Save the backup codes — yes, on paper

Every service hands you a short list of one-time backup codes when you switch two-factor on. Almost nobody saves them, and it is the single most common way people lock themselves out permanently. Print them and put the page somewhere that does not depend on the phone you are protecting — a drawer, a folder, a safe. Paper cannot be phished. Codes stored only on that phone are worthless the day it is lost.

A note on where the app lives: keeping your two-factor codes inside the same password manager that holds your passwords is convenient, and for most people the trade-off is fine. For a business's most sensitive accounts it puts both locks on one door — use a separate app or a hardware key there.

The lockout fear, answered honestly

The real reason most people never turn this on is not laziness. It is the fear of being locked out of their own accounts by their own security. That fear is not silly — it happens — but it is entirely manageable, because a true lockout requires losing every registered factor and the backup codes at the same time. So build in redundancy: register two methods wherever the service allows it — an app plus the printed codes, or an app plus a hardware key — and the loss of any one of them becomes an errand rather than an emergency.

If you are already on the wrong side of a locked account, there are recovery paths that work. And if you would rather have company for the whole job, a technician on Koadi can set everything up with you over a screen-share in under an hour.

Getting a new phone

Move your authenticator app before wiping the old handset. Most apps now offer an export or a cloud sync — use it while you still have both devices side by side. Doing this in the wrong order turns a ten-minute job into a week of identity checks with a dozen support desks.

If you run a business, make it policy

Asking staff nicely produces one colleague who never got around to it, and that is the mailbox the phishing email lands in — often followed by fake invoices sent to your customers. Microsoft 365 and Google Workspace both let an administrator require a second factor for every account in the company; turn the requirement on centrally and treat exceptions as temporary. You will not be early: in the same May 2026 FIDO survey, 68% of organisations had deployed passkeys for employee sign-in or were in the middle of doing so. Two-factor is one line of a longer list — the rest is in the small business cybersecurity checklist.

Twenty minutes of settings, or one job post

If working through settings pages is not how you want to spend an evening, post the job on Koadi free, in your own words — “set up two-factor on our email and bank accounts, and show me where the backup codes go” is plenty. Vetted, identity-verified technicians pick it up; you set a fixed price or take bids; payment sits in escrow until you approve the work. Remote help covers every US state, evenings and weekends included, and on-site visits are available through local technicians when you want someone in the room.

Frequently asked questions

Is two-factor authentication by text message safe enough?
It is far better than nothing — most account theft uses only a stolen password, and any second factor defeats that. But phone numbers can be moved to a criminal's SIM through a SIM swap, and texted codes can be phished in real time. Use an authenticator app or a passkey wherever the account offers one, and keep SMS only where nothing else exists.
What happens to my two-factor authentication if I lose my phone?
You sign in with one of the one-time backup codes the service gave you at setup, or restore your authenticator app from its sync or export onto the new phone. You are only truly locked out if you lose every registered factor and the codes at once — which is why the codes belong on paper, not on the phone itself.
Do I still need two-factor authentication if I use passkeys?
On an account where you sign in with a passkey, the passkey does both jobs — it proves the device and the person, and there is no password to steal. But most people still hold dozens of accounts that use passwords, and those need a second factor. Keep two-factor on everything until the password itself is gone.
Can two-factor authentication be hacked or bypassed?
Sometimes. Real-time phishing sites can relay app codes, and approval-fatigue attacks pester you with prompts until you tap yes. Both take far more effort than trying a leaked password, which is why attackers mostly move on to easier targets. Hardware keys and passkeys resist both tricks, because they only answer to the genuine site.

Still stuck?

Post this problem on Koadi — a vetted technician picks it up in minutes, and you don't pay until it's fixed.

Get a tech on it
← All fix-it guides