Two-factor authentication (2FA) adds a one-time code from your phone to your login, so a stolen password is no longer enough.
- Log in to the client area and open My Account → Security Settings.
- Choose Time-Based Tokens and scan the QR code with Google Authenticator, Authy or any TOTP app.
- Enter the current code to confirm, then save the backup code somewhere safe.
Do the same on your WordPress or Joomla admin login where a plugin offers it. If you lose the phone, the backup code or a support ticket with ID verification gets you back in.