What is multi-factor authentication, and what do you need to know to keep your accounts safe?
We use cookies to give users the best content and online experience. By clicking “Accept All Cookies”, you agree to allow us to use all cookies. Visit our Privacy Policy to learn more.
Chances are, when you log into your email, banking portal or other secure websites you’ll need some additional information – a code or a piece of information or a fingerprint. This is multi-factor authentication, and it's an additional safeguard to help protect your accounts from cyber attacks.
Multi-factor verification is a security best practice that requires a user to provide additional information along with a username and password in order to log into accounts.
This approach increases security because even if a password is hacked, there are additional steps that are likely out of the hacker’s reach.
The Cybersecurity and Infrastructure Security Agency classifies the types of MFA as being one of the following:
These additional pieces of identifying information are generally set up when you register an account on a website or app. You can also often add them later through the site or app’s user security settings.
One of the more common forms of MFA is six-digit verification codes. You’ll usually be sent these codes via either email or text. You can also sometimes request a phone call with the code.
Scammers know they need those codes to get into your accounts – so after they’ve acquired your password, they may pose as someone you trust, such as a representative from your bank or utility company, and ask for the code. If you give them the code, they can log in and access your personal information or money.
Verification code scams can also happen on social media. BBB has warned in the past about a scam on Facebook Marketplace where scammers posed as buyers and requested a seller’s phone number and six-digit code to “verify the seller is real.” The scammers were likely using the phone numbers to set up Google Voice accounts, which they then went on to use for other schemes or to commit identity fraud.