81% of US adults used multifactor authentication on at least one online account in May 2025, up from 76% two years earlier. Workforce coverage sits at 70%. Only 47% of UK businesses have it. This post breaks down two-factor authentication adoption across consumers, employees and businesses, the method mix behind those numbers, and what the attack data shows.
Two-Factor Authentication Adoption
How Many People Use Two-Factor Authentication?
Consumer Reports has asked US adults the same security questions three years running, which makes it one of the cleaner year-over-year series on consumer behaviour.
Use of multifactor authentication reached 81% in May 2025. The gain has slowed: four points between 2023 and 2024, one point in the year after.
Password managers moved faster, rising six points in a single year. Unique password use fell two points over the same three years, so some of the population is adding a second factor on top of recycled credentials rather than fixing the credential.
| Security habit | May 2023 | May 2024 | May 2025 |
|---|---|---|---|
| Use MFA on any online account | 76% | 80% | 81% |
| Require a password or PIN to unlock phone | 83% | 86% | 86% |
| Use a unique password per account | 67% | 65% | 65% |
| Change default passwords on devices | 59% | 61% | 65% |
| Use a password manager | 37% | 36% | 42% |
Source: Consumer Reports nationally representative American Experiences Surveys of 2,000 US adults (May 2023), 2,022 US adults (May 2024) and 2,333 US adults (May 2025). Base excludes respondents answering “not applicable”.
Two-Factor Authentication Methods: SMS Still Leads
Among Americans who use MFA, the method mix has barely moved, with one exception. Respondents could select every method they use, so the figures below do not sum to 100%.
SMS has held near 83% for three years despite being the method most exposed to SIM-swap attacks. That risk is the reason guidance on protecting a Google account on a Chromebook steers people toward prompts and hardware keys instead.
Passkeys entered the survey at 33% in their first year of measurement, ahead of phone-call authentication. Physical security keys sit at 5%, the same as in May 2024.
| MFA method | May 2023 | May 2024 | May 2025 |
|---|---|---|---|
| SMS or text-based code | 82% | 83% | 83% |
| Authenticator app (Google Authenticator, Duo) | 50% | 54% | 55% |
| Passkey | Not asked | Not asked | 33% |
| Phone call authentication | 26% | 25% | 24% |
| Physical security key | 6% | 5% | 5% |
Source: Consumer Reports American Experiences Surveys, May 2023, May 2024 and May 2025. Base: respondents who use multifactor authentication; multiple answers allowed.
Workforce Two-Factor Authentication Adoption Rates
Okta analysed billions of anonymised monthly authentications from its Workforce Identity commercial customers. Adoption rate here means the share of users who signed in with a given authenticator over a one-month period, measured as of January 2025.
Overall MFA adoption reached 70% of users. Okta notes that nearly a third of users still sign in without it.
Phishing-resistant authenticators grew from 8.6% to 14.0% of users, a 63% increase in twelve months by Okta’s calculation. Password use slipped from 95.1% to 93.0%, and 7% of users went the whole of January 2025 without entering a password at all.
| Authenticator | Jan 2024 | Jan 2025 |
|---|---|---|
| Password | 95.1% | 93.0% |
| SMS | 17.5% | 15.3% |
| Okta FastPass | 6.7% | 13.3% |
| Phishing-resistant combined | 8.6% | 14.0% |
Source: Okta Secure Sign-in Trends Report 2025, published December 2025. Users may use more than one authenticator, so figures do not sum.
Two-Factor Authentication Adoption By Industry
Most sectors land between 60% and 80%. Technology tops the list at 87%; transportation and warehousing sits at 42%.
Retail posted the largest year-over-year gain of any industry, nine percentage points. Okta records that retail was one of three industries targeted by the Scattered Spider group in early 2025, and says it expects further retail adoption following those events.
| Industry | Jan 2024 | Jan 2025 |
|---|---|---|
| Technology | Not disclosed | 87% |
| Healthcare and pharmaceuticals | 70% | 74% |
| Arts, entertainment, recreation | 63% | 68% |
| Retail | 43% | 52% |
| Transportation and warehousing | Not disclosed | 42% |
Source: Okta Secure Sign-in Trends Report 2025, data as of January 2025.
Adoption By Country
Asia-Pacific grew seven percentage points, from 61% to 68%, against two-point gains in the Americas and in Europe, the Middle East and Africa. Three markets drove it.
| Market | Jan 2024 | Jan 2025 |
|---|---|---|
| Hong Kong | 62% | 81% |
| South Korea | 63% | 80% |
| Japan | 53% | 62% |
| Asia-Pacific overall | 61% | 68% |
Source: Okta Secure Sign-in Trends Report 2025, data as of January 2025.
Two-Factor Authentication Adoption Among UK Businesses
The Cyber Security Breaches Survey 2025/2026 covered 2,112 UK businesses and 1,085 charities, with fieldwork between August and December 2025.
Two-factor authentication reached 47% of businesses, up from 40% the year before. It remains one of the least deployed controls on the list, behind malware protection at 81% and password policies at 74%.
The size gap is the finding. Large businesses run at 90%, micro businesses at 43%. Micro businesses drove the year’s increase, climbing from 35%, and DSIT attributes the overall uplift largely to that group.
VPN use follows the same laggard pattern at 36% of businesses, up from 31%. That tracks with wider VPN adoption rates by country.
| Organisation type | 2024/2025 | 2025/2026 |
|---|---|---|
| Large businesses (250+ staff) | Not disclosed | 90% |
| All businesses | 40% | 47% |
| Micro businesses (1–9 staff) | 35% | 43% |
| Charities | Not disclosed | 38% |
Source: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, fieldwork August to December 2025, published April 2026.
How Passkeys Are Changing Two-Factor Authentication
FIDO’s State of Passkeys 2026 surveyed 11,000 consumers and 1,400 enterprise decision-makers online across ten countries in April 2026. The consumer margin of error is 0.9 points.
Awareness reached 90%, with 7% saying they are not familiar with passkeys at all. Three-quarters have enabled one: 40% across most of their apps, 35% on a few.
Enabling and using are different things. Only 49% report using passkeys whenever possible or most of the time, and cross-ecosystem syncing explains part of the gap, as the mechanics of passkeys on Chromebooks show.
| Consumer metric (April 2026) | Share |
|---|---|
| Aware of passkeys | 90% |
| Enabled on at least some accounts | 75% |
| Use passkeys whenever possible or most of the time | 49% |
| Prefer passkeys over passwords at that frequency | 46% |
| Had a confirmed compromise or breach notice in the past year | 33% |
Source: FIDO Alliance, State of Passkeys 2026, consumer survey of 11,000 adults conducted by Sapio Research, April 2026.
Workforce Passkey Deployment
Among the 1,400 enterprise respondents, 68% have deployed, are deploying, or are piloting passkeys for employees. 82% say fully passwordless authentication is a goal they have reached or are pursuing, and 28% report it is already in place across most of the workforce.
Day-to-day reality lags the ambition. 57% still name a phishable method as the primary employee sign-in, against 30% naming a passkey-based method.
Legacy system compatibility is the most cited barrier at 38%, followed by budget approval at 35%. Recovery worries prove manageable once organisations start: 89% say they are confident they could restore access if a passkey were lost.
Source: FIDO Alliance, State of Passkeys 2026, workforce survey of 1,400 decision-makers at organisations with 500 or more employees, April 2026.
How Effective Is Two-Factor Authentication?
Microsoft found that 97% of identity attacks it observed were password spray attacks. Microsoft attributes this to attackers exploiting weak and overused passwords rather than to more sophisticated tactics.
The scale gives the number weight. Microsoft analyses 38 million identity risk detections on an average day, drawn from more than 100 trillion security signals processed daily.
Microsoft Entra reported blocking 7,000 password attacks per second in the year to November 2024, a 75% increase, and states that turning on MFA stops more than 99% of password-related attacks. Basic device hygiene compounds the benefit, which is covered in these Chromebook hardening steps and in this breakdown of how attackers get into a Chromebook.
Source: Microsoft Digital Defense Report 2025, published October 2025; Microsoft Entra blog, November 2024.
Two-Factor Authentication Adoption: What The Gaps Show
Three numbers frame the position. 81% of US adults use MFA somewhere, 70% of workforce users have it, and 47% of UK businesses require it.
The unprotected remainder is where attack volume lands. Hardware keys stay at 5% of US MFA users, though a Titan security key and the option to use a device PIN or fingerprint as a second factor both remove the SMS dependency.
FAQs
What percentage of people use two-factor authentication?
81% of US adults used multifactor authentication on at least one online account in May 2025, per Consumer Reports. In workplaces, Okta measured 70% of workforce users signing in with MFA as of January 2025.
What is the most common two-factor authentication method?
SMS codes. 83% of US adults who use MFA received a text-based code in May 2025, according to Consumer Reports. Authenticator apps came second at 55%, and passkeys reached 33% in their first year of measurement.
Why does Reddit warn against SMS two-factor authentication?
Reddit security threads flag SIM-swap risk, and the adoption data shows the exposure is widespread: SMS remains the top method at 83% of US MFA users, while physical security keys sit at 5%.
Are passkeys replacing two-factor authentication, according to Reddit users?
Reddit discussions usually describe passkeys as running alongside 2FA rather than replacing it, which matches FIDO’s April 2026 data: 75% of consumers have enabled a passkey, but only 49% use one whenever possible.
How many businesses require two-factor authentication?
47% of UK businesses had two-factor authentication in place in the 2025/2026 Cyber Security Breaches Survey, up from 40%. Large businesses reached 90%, while micro businesses reached 43%.
Sources
https://innovation.consumerreports.org/new-report-2025-consumer-cyber-readiness/
https://www.okta.com/newsroom/articles/secure-sign-in-trends-report-2025/
https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026
https://fidoalliance.org/the-state-of-passkeys-2026-global-consumer-and-workforce-report/
