Two-Factor Authentication (2FA)
✓ Last verified 14 Sep 2026
The short version
Two-factor authentication requires a second, independent proof of identity beyond just a password - typically an OTP or app-based approval - meaning a stolen password alone isn't enough for a fraudster to access your account.
Even if a password is compromised (through a data breach or phishing), 2FA requires a second factor - something you have (a phone receiving an OTP, an authenticator app) or something biometric - before access is granted, meaningfully raising the difficulty for a fraudster. See our safe digital banking habits article for where to enable this across your financial apps - it's one of the highest-value, lowest-effort security steps available.
Want this worked out for your own numbers?