What the research found
A study published in 2026 tracked what happened when three major Canadian banks rolled out two-factor authentication (2FA), the extra login step beyond just a password, during 2021–2022. Two banks made it optional. One made it mandatory. Researchers then analyzed cyber threat intelligence from criminal marketplaces to see which accounts were showing up as compromised.
Mandatory 2FA significantly reduced the number of compromised accounts. Optional 2FA did not, even though every customer had access to it. Having the option to be safer wasn’t enough. Only requiring it moved the needle.
This tracks with what large platforms report from their own systems. Microsoft has stated that MFA blocks over 99.9% of automated account-compromise attempts, and Google’s research shows that adding even a simple recovery phone number can block most bulk phishing and bot-driven attacks.
Why this matters for you personally
The lesson here is about human behavior. If 2FA sits as an optional toggle in your settings, the research suggests most people don’t turn it on, even when they know it helps. The fix is making the safer choice the default in your own digital life, right now, instead of waiting for “someday.”
Practical steps, in order of effectiveness:
Turn on 2FA for your email first. It’s the recovery key to everything else.
Prefer an authenticator app or a physical security key over SMS codes, which can be intercepted via SIM-swapping.
Do this for your bank and any account tied to money before anything else.
2FA isn’t perfect. SMS-based codes have known weaknesses, and no single measure eliminates risk. Treat it as a strong first layer of defense.
Reference
Kamar, E., et al. “Evaluating the Effectiveness of Two-Factor Authentication (2FA) in Mitigating Account Takeover Fraud: A Natural Experimental Study on Canadian Banks.” Sage Journals, 2026. https://doi.org/10.1177/00111287261441235

Top comments (0)