2-step verification is a login protection method that asks for a second proof of identity after the password. That second factor may be a time-based code, an authenticator app prompt, a hardware key, or a biometrics-backed approval. Even if an attacker steals a password through phishing, malware, or reuse from another breach, they still cannot log in without the extra factor.
It matters because passwords alone are easy to guess, reuse, or steal. In cyber security, 2-step verification is a common defense for email, gaming, banking, and cloud accounts, where one compromise can expose payments, contacts, or recovery options. Attackers often try to bypass it with fake login pages, SIM swaps, or prompt-fatigue attacks, so users should prefer app- or key-based methods over SMS when possible and treat unexpected verification requests as suspicious.


