July 11, 2026
What is phishing, and can 2FA stop it?
Phishing is the most common way accounts get stolen — and it doesn't rely on breaking anything. It relies on tricking you into typing your credentials into a page that isn't real.
How a phishing attack works
- You get an email, text, or DM that looks urgent: "unusual login," "verify your account," "your payment failed."
- It links to a page that looks exactly like the real login screen.
- You enter your password — straight into the attacker's hands.
The page is a copy. The logo, the layout, even the web address can be made to look almost right.
Does 2FA protect you?
Mostly, yes — and it's a big upgrade:
- Against leaked or guessed passwords, an authenticator app's TOTP code stops the attacker cold. They have your password but not your second factor.
- Against a live phishing page, be aware: a sophisticated fake can ask for your 6-digit code too and relay it in real time. TOTP raises the bar a lot, but it isn't magic. This is exactly where passkeys shine — they're tied to the real website and can't be handed to a fake one.
How to avoid the hook
- Don't click login links in messages. Type the address yourself or use a bookmark.
- Check the URL before entering anything.
- Slow down on urgency — that pressure is the whole trick.
- Never share a 2FA code with anyone, including "support." Real staff never ask.
Layer strong, unique passwords with an authenticator app and you'll shrug off the vast majority of attacks. Browse setup guides →