Skip to main content

Everything you need to know about 2-Step Verification (2FA)

Data breaches have only gotten bigger, bolder and more embarrassingly common. Passwords get stolen, guessed, phished and leaked in bulk every single day.

October 8, 2026
Aline Rivas, Head of Content & Social Media

Passwords are like the booking confirmation part of a tiny home. You’ve got the cutest getaway locked in, but it doesn’t mean you’re living it up in solitude just yet. Two-factor authentication, also known as 2FA, is the lock box code in your message thread, hidden behind a specific rock that’s hard to find. 

Just because you’ve got the confirmation email doesn’t guarantee you entry. You need a key.  

Passwords have great power for something we use so much in our day-to-day lives to protect everything from online banking to our work. But how safe are they, and can they provide protection in the event of a data breach like the recent Qantas hack?  

Talk about holidays.  

Data breaches have only gotten bigger, bolder and more embarrassingly common. Passwords get stolen, guessed, phished and leaked in bulk every single day. 

What's a normal person with a normal amount of online accounts supposed to do? Two-factor authentication. Scroll on to learn more.

TLDR

  • Passwords alone can be stolen. 2FA means a stolen password still can't get a hacker in. 

  • It works by combining something you know (your password) with something you have (your phone or an app). 

  • SMS codes are okay. Authenticator apps are better. Hardware keys are the gold standard. 

  • Enable it on your email, banking, social media and anything else that has personal information. Do it today. It takes four minutes. 

But what actually is 2FA?  

It’s an extra layer of protection and security. Security experts describe authentication as having three possible factors:  

  • Something you know – a password, a pin  

  • Something you have – a phone, an app, or a physical security key  

  • Something you are – a fingerprint or a face scan  

Most of us just log in using one factor. Two-factor authentication adds another factor. It’s in the name. That second one makes the difference between just getting annoyed at a data breach and finding out someone drained your bank account right before you’re about to buy Lady Gaga tickets.  

The three types of 2FA: Ranked  

Here are three types of two-factor authentication:  

SMS: Good, but vulnerable to SIM swapping   

An SMS 2FA is when a six-digit code arrives at your phone via text. Most people already know how it works.  

BUT! SMS codes can actually be intercepted through a SIM swap. This happens when a scammer convinces your phone carrier to transfer your number to a SIM card that they control.  

For everyday accounts, SMS 2FA is good to have. For banking or your email, you need to keep scrolling.  

Authenticator apps: Better.  

Apps like Google Authenticator, Microsoft Authenticator or Twilio Authy generate a fresh six-digit code every 30 seconds.  

It happens directly on your phone, with no SMS involved. No interception risk there, plus it works without mobile data.  

Setup involves scanning a QR code on the site you're securing and takes about 90 seconds. For most people, an authenticator app is the sweet spot between security and usability. 

Here’s a rundown of the most popular ones: 

App 

Best For 

Cost 

Google Authenticator 

Simplicity, most accounts 

Free 

Microsoft Authenticator 

Microsoft/work accounts 

Free 

Twilio Authy 

Encrypted backups, multi-device 

Free 

Duo Mobile 

Workplace/enterprise use 

Free 

Hardware keys: Best.  

Physical devices, like a YubiKey, that you plug into your computer or tap against your phone. Completely phishing-resistant. They’re impossible to intercept remotely. 

The downside for some? They cost money ($50–$100), not every site supports them yet and you need to not lose it.  

It’s well worth it if you’re in a high-risk industry or job like a journalist, activist, business owner or just anyone with a lot to protect.  

Where to turn it on 

Not sure where to start? Prioritise in this order…  

1. Email  

Your email is the master key to everything else. "Forgot your password?" links go to your inbox. If someone gets into your email, they can reset every other account you own. This one is non-negotiable. 

2. Banking and financial accounts  

Self-explanatory. Enable 2FA on every banking app, investment platform, and payment service you use. 

3. Social media  

Your Instagram, Facebook and TikTok accounts get targeted constantly, often to impersonate you or scam your followers. Don’t skip adding 2FA across all of them.  

4. The Superloop app   

Your Superloop account holds your personal details, payment information, and service settings.  

Superloop automatically uses multi-factor authentication (MFA) on our App and on SuperHub to protect exactly this. It's already built in, which means your account is safer before you've even done anything. 

5. Anywhere else that offers it  

Streaming services, cloud storage, work tools, and password managers. If the option exists, use it.

"But won't it be annoying?" 

Honestly? A little.  

After that, it becomes as automatic as unlocking your phone. Most apps keep you logged in on trusted devices, so you're not entering a code every single time — just when you log in somewhere new, or when something looks unusual. 

2FA adds roughly five seconds to your login. Recovering a hacked account takes hours, sometimes days, sometimes involves calling your bank, and crying to hold music sometimes.  

The five seconds are worth it for the peace of mind.  

Manage your account securely with the Superloop App 2.0  

You’ve spent this whole article learning about how to lock things down. So have we.  

Our Superloop App 2.0 has multi-factor authentication built in from the start. It’s easier to log in, pay securely within the app and you’re in full control of your account without ever having to leave this superpowered app.  

Your internet provider should hold itself to the same standards it’s recommending to you. We think so too. 

FAQ

It adds 5 seconds to your login but saves hours (not to mention the sweat, tears and swearing at your computer) of recovering a hacked account. Most services will keep you logged in on trusted devices, so you don’t need to be annoyed about entering a code every single time.  

This is a classic example of when backup codes come in handy. Most services give you "Backup Codes" when you set up 2FA. Keep these safe!  

Yes, we use MFA for logins for our app and the SuperHub portal to protect your personal data, billing information and account settings. It’s already in place, so your account is protected without you having to set anything up.  

In theory, it can. However, it is very difficult. Sophisticated phishing attempts can capture 2FA codes in real time, but it needs to be pretty targeted, which is why it’s quite rare. For the overwhelming amount of threats that most people face, 2FA is significantly safer.  

Written by

Aline Rivas
Head of Content & Social Media

I've spent the last 4 years at Superloop making complex telco topics genuinely easy to read, driven by a mission to help challenger telcos take on the big guys.

Related articles

Learn the challenges posed by internet-visible devices and the benefits of embracing cloud Networking and Security services (SASE) to enhance cybersecurity.

July 20, 2023

Cyberattacks take the number one spot in data breaches, and are increasing in sophistication and scope, according to the latest quarterly results from the April-June OAIC's Notifiable Data Breaches (NDB) scheme.

September 23, 2019

Let’s dissect these technologies, compare their features, and guide you through selecting the best fit for your organisational needs.

July 4, 2024

Refresh your internet

Type to show suggested addresses. Use the up and down arrow keys to move through the list, Enter to select an address, and Escape to close the listbox.