Every 2026 security report says the same thing: two-factor authentication (2FA) blocks the vast majority of account takeovers. Here's how to turn it on for your most important accounts.
Go to myaccount.google.com/security → "2-Step Verification" → follow the prompts.
Settings → "Accounts Centre" → "Password and security" → "Two-factor authentication."
Settings → your name → "Sign-In & Security" → "Two-Factor Authentication."
Look in your banking app's Security settings for "2-Step Verification" or "Login Approvals" — most NZ banks offer this by default now.
2FA means a stolen password alone isn't enough to get into your account. It's the single highest-impact thing on this entire site — if you do nothing else today, do this.
The vast majority of account takeovers start with a stolen or reused password. Two-factor authentication (2FA) means a password alone is no longer enough — an attacker also needs the second factor, which lives on your phone or a physical key. Even if your password appears in a data breach, 2FA keeps the account locked.
SMS codes can be intercepted through SIM-swap fraud, where a scammer convinces your phone company to transfer your number to their SIM. Authenticator apps generate codes on the device itself, so there is nothing to intercept. Use SMS only where an app is not supported — and never read a 2FA code to anyone who calls you. No legitimate company will ever ask.
Priority order: email first (it resets everything else), then banking and password manager, then social media, then shopping. If you only do three accounts this week, make them email, banking, and your password manager — those three protect everything downstream.
A password is one thing you know. If it leaks — through a breach, a phishing page, or malware on a machine you borrowed — whoever has it is you, as far as the service is concerned. Two-factor authentication adds a second, different kind of proof, so knowing the password is no longer sufficient.
The categories are traditionally described as something you know (a password), something you have (a phone, a security key), and something you are (a fingerprint or face). Real two-factor means combining two different categories. A password plus a security question is not two-factor: both are things you know, and the answers to security questions are often discoverable from public records or social media.
A code is texted to your phone. This is the most common method and the weakest of the real ones, because the code travels through the mobile network and can be intercepted. The main threat is SIM swapping: an attacker persuades or bribes a mobile provider to move your number to their SIM, and your codes then arrive on their phone. It happens, and it is particularly aimed at people with valuable accounts.
That said, SMS two-factor is enormously better than no two-factor. It defeats the automated credential stuffing that causes most account takeovers. If SMS is all a service offers, use it — then ask your mobile provider to add a port-out PIN or account lock to your number.
An app on your phone generates a six-digit code that changes every 30 seconds. The code is computed from a shared secret stored on your device and the current time, so it never travels over a network and cannot be intercepted in transit. This is the right default for most people and most accounts. It works offline, on a plane, and with no mobile signal.
Its weakness is phishing. A convincing fake login page can ask for the code and relay it to the real site within its 30-second window. The defence is the same as always: check the web address before typing anything.
The service sends a notification and you tap approve. Convenient, and it removes typing errors. The risk is habit — people tap approve reflexively. Attackers exploit this with "MFA fatigue", firing dozens of prompts at 3am until someone taps to make it stop. If your prompts show a number to match, that variant is much safer. If you ever get a prompt you did not trigger, deny it and change that password immediately, because it means someone already has it.
The strongest option available. A passkey is a cryptographic key stored on your phone, computer or a physical security key, unlocked by your fingerprint, face or a PIN. Nothing secret is ever typed or transmitted, so there is nothing for a phishing site to capture. Better still, the key is cryptographically bound to the real website's address and simply will not respond to a fake one. This makes passkeys genuinely phishing-proof rather than phishing-resistant.
When you switch on two-factor, the service offers a set of one-time backup codes. Save them. This is the difference between a lost phone being an annoyance and being a permanent lockout from your own email.
Store them somewhere that survives losing the phone: printed and kept with important documents, or in a password manager you can reach from another device. Do not store them as a screenshot on the same phone that generates the codes, which is the single most common mistake.
You do not have to do all of it in one sitting. Doing your email account today is worth more than planning to do everything next month.
Yes. It stops the automated attacks that cause the large majority of account takeovers. Use something stronger where it is offered, and ask your mobile provider for a port-out PIN to reduce the SIM swap risk.
You use the backup codes you saved when setting it up, which is why saving them matters so much. Most authenticator apps also offer an encrypted cloud backup so you can restore your codes onto a new device.
Yes, and most people should. One app can hold dozens of accounts. Protect the phone with a strong screen lock and make sure the app's backup is turned on.
A login method where your device proves who you are using a stored cryptographic key, unlocked by your fingerprint, face or PIN. There is no code to type and nothing a fake website can steal, which is why it is the strongest option available.
Deny every one of them and change that account's password straight away from a device you trust. Repeated unrequested prompts mean somebody already has your password and is trying to get you to tap approve out of frustration.