A few days ago, my wife received an email from a rather large airline. And there’s a good chance you, or someone you know, has received a similar email. It usually sounds something like this:

"We've been hacked… so that also means that you’ve been hacked. Because we were negligent (we take no legal responsibility, by the way), hackers now have all your private, personal, information. We are sorry. But we’re probably not gonna do much to stop this in the future. Okay Bye!"

Of course, my wife was rather upset by this. But she also knew this was my bag. So she texted me: "What do I do now?" Yes. What do you do when you know all your info is in the hands of a nefarious actor?

So what do you do? Call your congressperson and complain? Call a lawyer and sue? Cry?

It's a huge question, and one that, really, we shouldn’t have to answer. It really shouldn’t be up to us to deal with this. It should be on the companies to secure your data so hackers don't get it.

So what do you do? Call your congressperson and complain? Call a lawyer and sue? Cry? These are all legitimate reactions, so yes. Do all of them. But, when you’re done, there is a very simple, yet effective, step you can take to help keep yourself safe now that your info is all over the dark web.

It takes a bit of time and effort, but it's worth it: Just put MFA everywhere. For the love of God please.

To help her (and you) with this, I compiled a list of the top 100 most popular services used and how to find your MFA settings for every single one of them. Find the services you use, and implement MFA ASAP.

It's a boring statistic that most people don't pay attention to but adding multifactor authentication MASSIVELY reduces your risk. It makes account takeovers 96% less likely to happen. It makes it harder but passkeys are going to make things a little easier.

A secondary recommendation is to have Gemini or another AI, search your email and give you a summary list of the all services that you use.  From there you can ensure that you have MFA set up everywhere.  I know… This takes some work. But again, not that much considering the consequences.

So here are over 100 services that most everyone uses and how to enable MFA on your accounts. Below the table you find a nice glossary that explains exactly what each type of MFA is and does.  Enjoy!

Top 100+ Services with MFA Settings

Service MFA Options (summary) How to set it up (official link)
Google (Gmail/Account)
Passkeys, Authenticator app (TOTP), Google Prompt/Push, Security Key (FIDO2/U2F), SMS (backup)
Apple ID / iCloud
Passkeys, Apple device prompts (push), SMS/Voice (backup), Recovery Keys
Microsoft Account (Outlook/Office)
Authenticator app push, TOTP, Passkeys (WebAuthn), Security Key (FIDO2), SMS (backup)
Facebook (Meta)
Authentication app (TOTP), Passkeys (select regions), SMS (backup), Recovery codes
Instagram
Authentication app (TOTP), Passkeys (select regions), WhatsApp code, SMS (backup), Recovery codes
X (Twitter)
Passkeys (Web), Security key (FIDO2), Authentication app (TOTP) (paid for SMS), Recovery codes
LinkedIn
Authenticator app (TOTP), Passkeys (WebAuthn), SMS (backup), Recovery codes
Reddit
Authenticator app (TOTP), Security key (WebAuthn), SMS (legacy/limited)
TikTok
Passkeys (iOS/Android support varies), Authenticator app (TOTP), SMS (backup)
YouTube
Inherits Google Account MFA (see Google)
Amazon
Authenticator app (TOTP), SMS (backup), Security key (FIDO2 on some flows)
eBay
Authenticator app (TOTP), SMS (backup)
Walmart
Authenticator app (TOTP), Email/SMS (backup)
Etsy
Authenticator app (TOTP), SMS, Backup codes
Alibaba
Unverified - Authenticator app (TOTP), SMS, Email verification
Temu
SMS/Email codes, Authenticator app (limited), Device verification prompts
Shopify (merchant)
Authenticator app (TOTP), Security key (FIDO2), SMS (backup), Recovery codes
PayPal
Authenticator app (TOTP), SMS (backup)
Stripe (dashboard)
Authentication app (TOTP), Security key (FIDO2/WebAuthn), SMS (backup)
Cash App
"Security Lock", Device verification
Venmo
SMS codes, Authenticator app (limited), Device verification
Netflix
They uh, don't offer any
Spotify (for Artists)
Passkeys (supported), Authentication app (TOTP), SMS (backup) (rollout varies)
Disney+
None?
Hulu
Email/SMS verification links, Passkeys (rolling out), No classic TOTP
Prime Video (Amazon)
Inherits Amazon account MFA
Zoom
Authenticator app (TOTP), SMS (backup), Security key (WebAuthn), Passkeys
Slack
Authenticator app (TOTP), SMS (paid/SSO limits), Security key (WebAuthn), Enterprise SSO MFA
Dropbox
Authenticator app (TOTP), Security key (WebAuthn), SMS (backup), Backup codes
Box
Authenticator app (TOTP), SMS, Security key (WebAuthn) (Enterprise)
Evernote
Authenticator app (TOTP), SMS (backup)
Uber
Device verification, Passkeys (rolling out), No classic TOTP
Lyft
SMS login codes, Device verification
Airbnb
Authenticator app (TOTP), SMS (backup), Email, Passkeys (rolling out)
Booking.com
Authenticator app (TOTP) for partners, SMS/Email for guests, Device verification
Expedia
SMS/Email codes, Device verification
Delta Air Lines
SMS/Email codes, App verification (Fly Delta), Device verification
United Airlines
SMS/Email codes, App verification, Device verification
American Airlines
SMS/Email codes, App verification, Device verification
Southwest Airlines
SMS/Email codes, App verification
Air Canada
SMS/Email codes, App verification
Instacart
SMS codes, Email codes, Device verification
Kroger
Email/SMS codes, Device verification
Costco
Email/SMS verification, Device verification
DoorDash
SMS codes, 2-step verification, Device verification
Uber Eats
Inherits Uber account protections (device verification)
Grubhub
SMS/Email codes, Device verification
Verizon
Account PIN, SMS/Email codes, Number Lock, Two-step verification
AT&T
Account passcode, SMS codes, Two-step verification
T-Mobile
Account PIN/Passcode, SMS codes, App verification
Chase
One-time codes via SMS/Email/Phone, Device approval, Security Key support for business (limited)
Bank of America
SafePass SMS/Email, Authenticator app (soft token), Device approval
Wells Fargo
Advanced Access SMS/Voice, App notifications, Device approval
Citi
SMS/Email codes, App push notifications
Capital One
SMS/Email codes, App push notifications, Device approval
American Express
Authenticator app (soft token), SMS/Email codes, Push notifications
RBC (Canada)
SMS/Email codes, RBC app verification, Interac 2SV
TD (Canada)
SMS/Email codes, TD app verification
HSBC
Digital Secure Key (app/hardware), SMS codes
Nubank (Brazil)
App-based verification, Device pairing, Email/SMS codes
HDFC Bank (India)
SMS OTP, App authentication, Device binding
ICICI Bank (India)
SMS OTP, App push, Device registration
GTBank (Nigeria)
SMS/Email OTP, Hardware token (for transfers), App verification
GEICO
SMS/Email codes, Device verification
Progressive
SMS/Email codes, App verification
State Farm
SMS/Email codes, App verification
USPS
SMS/email OTP, Device verification
UPS
SMS/email codes, Device verification
FedEx
SMS/email codes, Security Qs, Device verification
DHL Express
SMS/email codes, Device verification
Zillow
Email/SMS login codes
Realtor.com
Email/SMS login codes
realtor.ca
Email/SMS login codes
Idealista
Email login verification
DocuSign
Authenticator app (TOTP), SMS (backup), Email verification
Square
Authenticator app (TOTP), SMS, Email
Twitch
Authenticator app (TOTP), SMS (backup)
Pinterest
SMS/email codes, Authenticator app (TOTP)
Telegram
Password + SMS login, Cloud password (2FA)
Signal
PIN lock, Registration lock
LINE
PIN + SMS verification
WeChat
Device verification, WeChat password
BiliBili
SMS/email codes, Device verification
Vimeo
Authenticator app (TOTP), SMS/email codes
NYTimes
Authenticator app (TOTP), SMS/email codes
CNN
Email verification, Device verification
BBC
BBC account sign-in verification
Kayak
Email/SMS login codes
TripAdvisor
Email/SMS login codes
Skyscanner
Email/SMS login codes
Agoda
Email/SMS codes
IRS.gov
Security code via SMS/Voice/Authenticator app (ID.me)
Social Security (SSA.gov)
SMS/email codes, Authenticator app (TOTP)
Canada Revenue Agency (CRA)
Passcodes via SMS/Voice, Security Qs
HMRC (UK)
SMS/Voice codes, Authenticator app (TOTP)
USCIS
SMS/email codes
Target
SMS/email codes
Best Buy
SMS/email codes
Home Depot
SMS/email codes
Lowe's
SMS/email codes
Macy's
SMS/email codes
McDonald's App
SMS/email verification
Starbucks
SMS/email codes, Device verification
Subway
SMS/email verification
Banco do Brasil
App token, SMS codes
Santander (Spain/Global)
App token, SMS codes
Barclays
PINsentry card reader, Mobile app auth, SMS codes
NatWest
Card reader, Mobile app verification
ANZ Bank
App verification, SMS OTP
Commonwealth Bank (CBA AU)
NetCode SMS, App verification
Standard Bank (South Africa)
App OTP, SMS OTP
Absa Bank (South Africa)
App OTP, SMS OTP

If you can't find your service here, there is a fantastic crowdsourced directory called https://2fa.directory/us/

And finally here is a simple glossary of all the different types of Multifactor Authentication you can use on your accounts.

Glossary: 

MFA - The most important thing in this article! This stands for Multi-Factor Authentication and is used to provide extra protection to online accounts.  This is often considered a secondary factor after using a password to protect an account.

SMS Code - The service will send you a text message with a 6 digit code or link that you can click to verify it's actually you accessing the service.  This is secure because it's difficult to guess a 6 digit code and it's difficult to spoof a cellphone via sms number (but unfortunately not THAT difficult).

Email Code - The service will send you an email with a 6 digit code or a "magic link" that will allow you to login.  This is secure because as long as you keep your email safe the login link is secure.

Authenticator App - This is actually one of the most secure ways to add Multi-factor protection.  The app will generate a 6 digit code that typically changes every 30 seconds.  Your application needs to be in sync with the service you are trying to log into.  This is also called TOTP.

TOTP Code - This is the same as the above.  There are many different Authenticator apps but most of them support Time-Based One Time Passwords.

App Verification or App Push Notification - This is also a very secure way to do MFA.  This mode usually occurs by the service sending a notification to your phone within the app they control.  Thus they know if you receive and confirm the push that it is in fact you trying to access the service.

Passkey - A passkey is a newer very cool way to create a handshake between your browser and your device.  A service can send you a passkey link or when you try to go to a website the website will ask the browser to ask your device to ask you (phew) to identify yourself to the device.  This often happens with TouchID or FaceID or a pin or other biometric method.

WebAuthn - This is another term for passkeys but also relates to FIDO keys.  See below.

Fido Key - This is a hardware device that often connects via USB or another mechanism that can generate a secure token on your behalf.  It is similar to a passkey in that it will connected with your device which in turn connects to the service you are trying to access.

Voice call - Sometimes services will support calling a phone number and delivering you a 6 digit code that you can say or enter into the login portal when you are trying to access a service.

All told, there are plenty of ways to secure accounts, but not all are equal. If you want to cut through the noise, we recommend TOTP and Passkeys as they are the most secure. SMS and email are fallback options.

MFA, though, is only the first line of defense. For individuals, it can mean the difference between a breach and a block. For organizations, it has to scale across help desks, PSAs, and chat platforms where attackers are most aggressive. At the organizational level, the same protections have to be enforced inside the systems where work actually happens. Traceless provides that layer by making sure security checks and safe exchanges are built into everyday workflows. In practice, that means:

  • Identity verification directly inside tickets and chats
  • Secure file transfers of up to 200GB
  • Ephemeral messaging so sensitive data never lingers in logs
  • MFA push notifications triggered right from help desks and PSAs
  • Password resets with automatic audit trails created in the system of record
  • SOC 2 certification for compliance assurance
  • A setup process that takes less than 10 minutes, with integrations for the tools you already use
  • A free, unlimited 30-day trial, then simple month-to-month billing with no contract

So yes, MFA everywhere. Start with the list, check your accounts, and build the habit. And if you run an organization, extend the same discipline into your daily workflows with systems that make identity checks and secure exchanges unavoidable.

If your organization handles sensitive approvals or system access, those interactions are now prime targets for AI-driven impersonation. Traceless integrates with your existing tools in under 10 minutes, adding identity verification and ephemeral messaging that make these attacks significantly harder to pull off. Book a demo to see how it works.