Two-Factor Authentication Adoption Statistics 2026

Two-Factor Authentication Adoption Statistics 2026

81% of US adults used multifactor authentication on at least one online account in May 2025, up from 76% two years earlier. Workforce coverage sits at 70%. Only 47% of UK businesses have it. This post breaks down two-factor authentication adoption across consumers, employees and businesses, the method mix behind those numbers, and what the attack data shows.

Two-Factor Authentication Adoption

81%of US adults use multifactor authentication on at least one online accountConsumer Reports, May 2025
70%of Okta workforce users signed in using MFA over a one-month periodOkta, January 2025
47%of UK businesses have any two-factor authentication for networks or applicationsDSIT, 2025/2026
83%of US MFA users get a code by SMS, the most common methodConsumer Reports, May 2025
75%of consumers surveyed have enabled a passkey on at least some accountsFIDO Alliance, April 2026
97%of identity attacks Microsoft observed were password spray attacksMicrosoft Digital Defense Report 2025

How Many People Use Two-Factor Authentication?

Consumer Reports has asked US adults the same security questions three years running, which makes it one of the cleaner year-over-year series on consumer behaviour.

Use of multifactor authentication reached 81% in May 2025. The gain has slowed: four points between 2023 and 2024, one point in the year after.

Password managers moved faster, rising six points in a single year. Unique password use fell two points over the same three years, so some of the population is adding a second factor on top of recycled credentials rather than fixing the credential.

Security habit May 2023 May 2024 May 2025
Use MFA on any online account 76% 80% 81%
Require a password or PIN to unlock phone 83% 86% 86%
Use a unique password per account 67% 65% 65%
Change default passwords on devices 59% 61% 65%
Use a password manager 37% 36% 42%

Source: Consumer Reports nationally representative American Experiences Surveys of 2,000 US adults (May 2023), 2,022 US adults (May 2024) and 2,333 US adults (May 2025). Base excludes respondents answering “not applicable”.

Two-Factor Authentication Methods: SMS Still Leads

Among Americans who use MFA, the method mix has barely moved, with one exception. Respondents could select every method they use, so the figures below do not sum to 100%.

SMS has held near 83% for three years despite being the method most exposed to SIM-swap attacks. That risk is the reason guidance on protecting a Google account on a Chromebook steers people toward prompts and hardware keys instead.

Passkeys entered the survey at 33% in their first year of measurement, ahead of phone-call authentication. Physical security keys sit at 5%, the same as in May 2024.

MFA method May 2023 May 2024 May 2025
SMS or text-based code 82% 83% 83%
Authenticator app (Google Authenticator, Duo) 50% 54% 55%
Passkey Not asked Not asked 33%
Phone call authentication 26% 25% 24%
Physical security key 6% 5% 5%

Source: Consumer Reports American Experiences Surveys, May 2023, May 2024 and May 2025. Base: respondents who use multifactor authentication; multiple answers allowed.

Workforce Two-Factor Authentication Adoption Rates

Okta analysed billions of anonymised monthly authentications from its Workforce Identity commercial customers. Adoption rate here means the share of users who signed in with a given authenticator over a one-month period, measured as of January 2025.

Overall MFA adoption reached 70% of users. Okta notes that nearly a third of users still sign in without it.

Phishing-resistant authenticators grew from 8.6% to 14.0% of users, a 63% increase in twelve months by Okta’s calculation. Password use slipped from 95.1% to 93.0%, and 7% of users went the whole of January 2025 without entering a password at all.

Authenticator Jan 2024 Jan 2025
Password 95.1% 93.0%
SMS 17.5% 15.3%
Okta FastPass 6.7% 13.3%
Phishing-resistant combined 8.6% 14.0%

Source: Okta Secure Sign-in Trends Report 2025, published December 2025. Users may use more than one authenticator, so figures do not sum.

Two-Factor Authentication Adoption By Industry

Most sectors land between 60% and 80%. Technology tops the list at 87%; transportation and warehousing sits at 42%.

Retail posted the largest year-over-year gain of any industry, nine percentage points. Okta records that retail was one of three industries targeted by the Scattered Spider group in early 2025, and says it expects further retail adoption following those events.

Industry Jan 2024 Jan 2025
Technology Not disclosed 87%
Healthcare and pharmaceuticals 70% 74%
Arts, entertainment, recreation 63% 68%
Retail 43% 52%
Transportation and warehousing Not disclosed 42%

Source: Okta Secure Sign-in Trends Report 2025, data as of January 2025.

Adoption By Country

Asia-Pacific grew seven percentage points, from 61% to 68%, against two-point gains in the Americas and in Europe, the Middle East and Africa. Three markets drove it.

Market Jan 2024 Jan 2025
Hong Kong 62% 81%
South Korea 63% 80%
Japan 53% 62%
Asia-Pacific overall 61% 68%

Source: Okta Secure Sign-in Trends Report 2025, data as of January 2025.

Two-Factor Authentication Adoption Among UK Businesses

The Cyber Security Breaches Survey 2025/2026 covered 2,112 UK businesses and 1,085 charities, with fieldwork between August and December 2025.

Two-factor authentication reached 47% of businesses, up from 40% the year before. It remains one of the least deployed controls on the list, behind malware protection at 81% and password policies at 74%.

The size gap is the finding. Large businesses run at 90%, micro businesses at 43%. Micro businesses drove the year’s increase, climbing from 35%, and DSIT attributes the overall uplift largely to that group.

VPN use follows the same laggard pattern at 36% of businesses, up from 31%. That tracks with wider VPN adoption rates by country.

Organisation type 2024/2025 2025/2026
Large businesses (250+ staff) Not disclosed 90%
All businesses 40% 47%
Micro businesses (1–9 staff) 35% 43%
Charities Not disclosed 38%

Source: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, fieldwork August to December 2025, published April 2026.

How Passkeys Are Changing Two-Factor Authentication

FIDO’s State of Passkeys 2026 surveyed 11,000 consumers and 1,400 enterprise decision-makers online across ten countries in April 2026. The consumer margin of error is 0.9 points.

Awareness reached 90%, with 7% saying they are not familiar with passkeys at all. Three-quarters have enabled one: 40% across most of their apps, 35% on a few.

Enabling and using are different things. Only 49% report using passkeys whenever possible or most of the time, and cross-ecosystem syncing explains part of the gap, as the mechanics of passkeys on Chromebooks show.

Consumer metric (April 2026) Share
Aware of passkeys 90%
Enabled on at least some accounts 75%
Use passkeys whenever possible or most of the time 49%
Prefer passkeys over passwords at that frequency 46%
Had a confirmed compromise or breach notice in the past year 33%

Source: FIDO Alliance, State of Passkeys 2026, consumer survey of 11,000 adults conducted by Sapio Research, April 2026.

Workforce Passkey Deployment

Among the 1,400 enterprise respondents, 68% have deployed, are deploying, or are piloting passkeys for employees. 82% say fully passwordless authentication is a goal they have reached or are pursuing, and 28% report it is already in place across most of the workforce.

Day-to-day reality lags the ambition. 57% still name a phishable method as the primary employee sign-in, against 30% naming a passkey-based method.

Legacy system compatibility is the most cited barrier at 38%, followed by budget approval at 35%. Recovery worries prove manageable once organisations start: 89% say they are confident they could restore access if a passkey were lost.

Source: FIDO Alliance, State of Passkeys 2026, workforce survey of 1,400 decision-makers at organisations with 500 or more employees, April 2026.

How Effective Is Two-Factor Authentication?

Microsoft found that 97% of identity attacks it observed were password spray attacks. Microsoft attributes this to attackers exploiting weak and overused passwords rather than to more sophisticated tactics.

The scale gives the number weight. Microsoft analyses 38 million identity risk detections on an average day, drawn from more than 100 trillion security signals processed daily.

Microsoft Entra reported blocking 7,000 password attacks per second in the year to November 2024, a 75% increase, and states that turning on MFA stops more than 99% of password-related attacks. Basic device hygiene compounds the benefit, which is covered in these Chromebook hardening steps and in this breakdown of how attackers get into a Chromebook.

Source: Microsoft Digital Defense Report 2025, published October 2025; Microsoft Entra blog, November 2024.

Two-Factor Authentication Adoption: What The Gaps Show

Three numbers frame the position. 81% of US adults use MFA somewhere, 70% of workforce users have it, and 47% of UK businesses require it.

The unprotected remainder is where attack volume lands. Hardware keys stay at 5% of US MFA users, though a Titan security key and the option to use a device PIN or fingerprint as a second factor both remove the SMS dependency.

FAQs

What percentage of people use two-factor authentication?

81% of US adults used multifactor authentication on at least one online account in May 2025, per Consumer Reports. In workplaces, Okta measured 70% of workforce users signing in with MFA as of January 2025.

What is the most common two-factor authentication method?

SMS codes. 83% of US adults who use MFA received a text-based code in May 2025, according to Consumer Reports. Authenticator apps came second at 55%, and passkeys reached 33% in their first year of measurement.

Why does Reddit warn against SMS two-factor authentication?

Reddit security threads flag SIM-swap risk, and the adoption data shows the exposure is widespread: SMS remains the top method at 83% of US MFA users, while physical security keys sit at 5%.

Are passkeys replacing two-factor authentication, according to Reddit users?

Reddit discussions usually describe passkeys as running alongside 2FA rather than replacing it, which matches FIDO’s April 2026 data: 75% of consumers have enabled a passkey, but only 49% use one whenever possible.

How many businesses require two-factor authentication?

47% of UK businesses had two-factor authentication in place in the 2025/2026 Cyber Security Breaches Survey, up from 40%. Large businesses reached 90%, while micro businesses reached 43%.

Sources

https://innovation.consumerreports.org/new-report-2025-consumer-cyber-readiness/
https://www.okta.com/newsroom/articles/secure-sign-in-trends-report-2025/
https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
https://fidoalliance.org/the-state-of-passkeys-2026-global-consumer-and-workforce-report/