EN RU
List your company
Technology

2FA (two-factor authentication)

Two-factor authentication (2FA), a form of multi-factor authentication, requires a user to present two different types of evidence to log in: something…

By Anders Lindqvist · CBDM Updated 6 September 2026

Definition

Two-factor authentication (2FA), a form of multi-factor authentication, requires a user to present two different types of evidence to log in: something they know (a password) plus something they have (a code from an authenticator app, an SMS one-time code, a hardware key) or something they are (a biometric). The second factor means a stolen or guessed password alone is not enough to access the account.

In iGaming, 2FA protects player accounts that hold balances and personal data, and — just as importantly for affiliates and media buyers — it protects the operational accounts a business depends on: ad platforms, affiliate networks, payment providers, domain registrars, email and hosting. Losing one of those accounts to a credential theft can halt an operation, so 2FA on every business-critical account is a baseline security practice.

Browse iGaming software platforms

In context

The factor types differ in strength. SMS codes are better than nothing but vulnerable to SIM-swap attacks, where an attacker ports the victim's number; authenticator apps (TOTP) are stronger because the code is generated on the device and never transmitted; hardware security keys (FIDO2/WebAuthn) are the strongest common option because they are phishing-resistant — the key verifies the site's identity, so a fake login page cannot capture a usable credential.

For high-value operational accounts, teams increasingly standardise on hardware keys or app-based 2FA and disable SMS as a fallback where possible.

For operators, 2FA design is a conversion-versus-security trade-off on the player side: forcing 2FA at registration adds friction and loses some sign-ups, so many operators make it optional at first and mandatory at withdrawal or on risk triggers. Regulators in some markets require strong customer authentication for payments, which pushes 2FA into the deposit and withdrawal flow regardless.

The common failures are relying on SMS alone for critical accounts, not enforcing 2FA across a whole team (one un-protected account is the weak link), and having no recovery plan for a lost second factor, which can lock a business out of its own ad accounts.

Worked example

A media-buying team loses access to a Business Manager after a phishing email captures a password; the account had only SMS 2FA and the attacker performed a SIM swap. The team migrates every operational account to app-based or hardware-key 2FA, removes SMS fallback, and stores recovery codes offline in a shared vault.

Related terms

Frequently asked questions

What does 2FA (two-factor authentication) mean?+
Two-factor authentication (2FA), a form of multi-factor authentication, requires a user to present two different types of evidence to log in: something they know (a password) plus something they have (a code from an authenticator app, an S…
Where is 2FA (two-factor authentication) used?+
The factor types differ in strength.
Can you give an example of 2FA (two-factor authentication)?+
A media-buying team loses access to a Business Manager after a phishing email captures a password; the account had only SMS 2FA and the attacker performed a SIM swap. The team migrates every operational account to app-based or hardware-key 2FA, removes SMS fallback, and stores recovery codes offline in a shared vault.
What terms are related to 2FA (two-factor authentication)?+
2FA (two-factor authentication) is closely related to KYC, Verification, Account ban, Phishing, Ad account. Links to each are in the related-terms block below.
Why does 2FA (two-factor authentication) matter for operators and affiliates?+
A shared understanding of 2FA (two-factor authentication) keeps deal terms, reporting and platform requirements in iGaming technology unambiguous between partners.
How is 2FA (two-factor authentication) different from adjacent concepts?+
The scope of 2FA (two-factor authentication) and how it differs from neighbouring concepts is covered in the definition and the related-terms block on this page.
Who owns 2FA (two-factor authentication) inside an iGaming company?+
Ownership is shared between the relevant specialist team, analytics and product leadership.
Where can I learn more about 2FA (two-factor authentication)?+
The full iGamingB2B glossary carries hundreds of EN/RU definitions — use the search and A–Z index on the glossary page.
Next → 3-D Secure (3DS)

Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.

← Back to glossary