SMS is the weakest form of two-factor authentication, and it is the one almost every Indian account relies on. An attacker who obtains a duplicate SIM in your name receives every code sent to your number — which is not a theoretical risk here, it is a well-documented category of fraud.
Turning on stronger second factors takes about fifteen minutes across your main accounts. Here is where to do it and what to choose.
The Hierarchy, Strongest First
- Hardware security key — a physical device. Strongest available, and overkill for most people.
- Passkey — cryptographic, tied to your device biometrics. Increasingly the best practical option.
- Authenticator app — codes generated on your device, never transmitted. The right default.
- SMS OTP — better than nothing, and vulnerable to SIM swap.
The jump from SMS to an authenticator app is the one that matters. Everything above that is refinement.
Start here, because your Google account is the recovery route for most of your other accounts. If it falls, everything else follows.
Go to myaccount.google.com → Security → 2-Step Verification.
- Add an authenticator app as your primary second factor.
- Generate backup codes — ten single-use codes. Print them or write them down somewhere physical. This is your escape hatch when a phone is lost.
- Consider adding a passkey for passwordless sign-in.
- Keep SMS as a fallback rather than the primary method.
While you are there, review the devices list and remove anything you no longer own. Our guide to recovering a Google account without the phone number explains why this setup matters so much.
WhatsApp’s protection is different in kind, and widely misunderstood.
Go to Settings → Account → Two-step verification and set a six-digit PIN.
This PIN is required whenever your number is registered on WhatsApp on a new device. It means that even if someone controls your number and receives the registration SMS, they still cannot complete the takeover without the PIN.
Given how much of an Indian phone’s life runs through WhatsApp — and how effective account takeover is at defrauding your contacts — this is arguably the single highest-value five seconds in this article. Add a recovery email address at the same time, or a forgotten PIN locks you out for days.
Settings → Accounts Centre → Password and security → Two-factor authentication.
Choose the authentication app option rather than SMS. Instagram accounts are targeted heavily for resale and for running scams against your followers, and recovery through the platform is notoriously slow — prevention is worth considerably more than the cure here.
Save the recovery codes it offers.
Banking and UPI
These mostly do not offer app-based 2FA in the way Google does; they use their own device binding, MPINs and SMS OTP.
What you can control: set a strong app lock or biometric on each banking app, never save UPI PINs anywhere, and keep the number registered with your bank private. Using a separate, unpublished number for banking is one of the more effective habits available, for the reasons set out in our guide to SIM swap fraud.
Which Authenticator App?
Google Authenticator, Microsoft Authenticator and Authy all work. The important consideration is not which one but what happens when you lose the phone.
Some sync codes to a cloud account; some do not. If yours does not, and you wipe the handset without exporting, you lose every code at once. Check which behaviour yours has, and if it offers cloud sync, decide deliberately whether you want it — sync is more convenient and slightly less private.
Whichever you choose, migrate it deliberately when you change phones, as covered in our guide to moving to a new phone without losing data.
Backup Codes: The Part Everyone Skips
Every service that offers 2FA also offers backup codes, and almost nobody saves them. They are the only reliable route back into an account when your phone is lost, stolen or bricked.
Print them. Keep them with your important documents, not in a note on the phone they are meant to rescue you from. Treat them like a spare house key.
A Fifteen-Minute Pass
Google first, with an authenticator app and saved backup codes. WhatsApp PIN and recovery email. Instagram on an authenticator. Then your email provider if it is not Google, and any account holding money.
Do the same for your parents. Older relatives are targeted disproportionately and are least likely to have moved off SMS. We publish practical Indian security guidance at Techleez com.
Where 2FA Does Not Save You
Worth being clear about the limits, because a false sense of completeness is its own risk.
Two-factor authentication protects the login. It does nothing against a scam where you willingly authorise a payment, approve a collect request, or read a code aloud to someone claiming to be from your bank. A great deal of Indian fraud never touches your password at all — it persuades you to act.
It also does not help if you approve the prompt without reading it. Push-based approvals train people to tap “Yes” reflexively, and attackers exploit exactly that by firing repeated requests until someone taps to make the buzzing stop. If a prompt arrives when you are not logging in, the answer is always no, followed by a password change.
And it does not protect an account whose recovery route is weak. An attacker who cannot pass your second factor may simply attack your recovery email or your phone number instead. Securing the front door while leaving the back door on SMS is a common and expensive mistake.
Check What Is Already Signed In
Once your second factors are in place, spend two minutes reviewing active sessions on each service. Google lists them under Security, WhatsApp under Linked Devices, and Instagram under login activity.
Look for devices and locations you do not recognise, and for linked-device entries on WhatsApp that you never authorised — WhatsApp Web sessions left open on a shared or office computer are a quiet and very common exposure. Sign out of everything you cannot account for, then change the password.
Frequently Asked Questions
Is SMS OTP safe enough?
It is better than nothing, but it is the weakest option and vulnerable to SIM swap. Move critical accounts to an authenticator app.
What does WhatsApp two-step verification actually do?
It sets a six-digit PIN required whenever your number is registered on a new device, so controlling your number alone is not enough to take over your account.
What happens if I lose the phone with my authenticator app?
You use your saved backup codes. If the app syncs to a cloud account, you can restore it there. Without either, recovery is slow and sometimes impossible.
Which authenticator app is best?
They are broadly equivalent. What matters is knowing whether yours syncs to the cloud, so you know what happens when the phone is gone.
Should I set up 2FA on banking apps?
Banking apps use their own device binding and MPINs rather than standard 2FA. Set a biometric app lock and keep your banking number private.
Where should I keep backup codes?
Printed or written down with your important documents — not in a note on the phone they exist to replace.
