What it means
Factors describe what you know, have or are. Two passwords are still one factor type. An authenticator code, security key or suitably protected passkey can provide additional evidence. Codes and push approvals can be tricked or relayed; availability of phishing-resistant methods depends on the service.
How this affects everyday use
Account takeover often begins with reused passwords, a convincing false sign-in page or an unexpected approval request. Lost phones can also leave legitimate users unable to sign in.
A practical example
An email password leaks from another website. A separate security key can prevent that password alone from opening the mailbox, provided the recovery route is also protected.
What to check
- Check which verification methods the account actually accepts.
- Review backup codes, recovery contacts and registered devices.
- Inspect recent sign-ins and prompts you did not initiate.
Practical next steps
- Register a stronger supported method from the genuine account settings.
- Store recovery codes separately from the everyday sign-in device.
- Reject unexpected prompts and revoke unknown devices or sessions.
Keeping it reliable
Plan recovery before replacing a phone. Use unique passwords, keep spare verification methods secure and periodically review them. MFA reduces particular risks; it does not make an infected or unlocked device safe.