Definition
Two-factor authentication (2FA), a form of multi-factor authentication, requires a user to present two different types of evidence to log in: something they know (a password) plus something they have (a code from an authenticator app, an SMS one-time code, a hardware key) or something they are (a biometric). The second factor means a stolen or guessed password alone is not enough to access the account.
In iGaming, 2FA protects player accounts that hold balances and personal data, and — just as importantly for affiliates and media buyers — it protects the operational accounts a business depends on: ad platforms, affiliate networks, payment providers, domain registrars, email and hosting. Losing one of those accounts to a credential theft can halt an operation, so 2FA on every business-critical account is a baseline security practice.
In context
The factor types differ in strength. SMS codes are better than nothing but vulnerable to SIM-swap attacks, where an attacker ports the victim's number; authenticator apps (TOTP) are stronger because the code is generated on the device and never transmitted; hardware security keys (FIDO2/WebAuthn) are the strongest common option because they are phishing-resistant — the key verifies the site's identity, so a fake login page cannot capture a usable credential.
For high-value operational accounts, teams increasingly standardise on hardware keys or app-based 2FA and disable SMS as a fallback where possible.
For operators, 2FA design is a conversion-versus-security trade-off on the player side: forcing 2FA at registration adds friction and loses some sign-ups, so many operators make it optional at first and mandatory at withdrawal or on risk triggers. Regulators in some markets require strong customer authentication for payments, which pushes 2FA into the deposit and withdrawal flow regardless.
The common failures are relying on SMS alone for critical accounts, not enforcing 2FA across a whole team (one un-protected account is the weak link), and having no recovery plan for a lost second factor, which can lock a business out of its own ad accounts.
Worked example
A media-buying team loses access to a Business Manager after a phishing email captures a password; the account had only SMS 2FA and the attacker performed a SIM swap. The team migrates every operational account to app-based or hardware-key 2FA, removes SMS fallback, and stores recovery codes offline in a shared vault.
Related terms
Frequently asked questions
Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.
← Back to glossary