Instagram two-factor authentication.
Two minutes. Account locked tight.
With 2FA on, a stolen password opens nothing — logins on new devices need a code only your phone can produce. Setup, the right method to pick, and the lost-phone escape routes, all below.
Turn it on in four steps
1. Password and security
Settings and privacy → Accounts Center → Password and security → Two-factor authentication.
2. Pick your account
Choose the profile you're protecting (each account has its own 2FA).
3. Choose authenticator app
Scan the QR with Google Authenticator, Authy or your password manager and enter the 6-digit code. Skip SMS unless it's your only option.
4. Save backup codes
Additional methods → Backup codes. Five single-use codes — store them anywhere that isn't the phone they're rescuing you from.
Which second factor?
Authenticator app · best
Codes generated on-device, immune to SIM-swapping and SMS interception. Works offline. Any TOTP app does it — Google Authenticator, Authy, 1Password.
Passkey · simplest
Face ID / fingerprint instead of codes, phishing-resistant by design. Supported on modern iPhones and Androids — great as the primary if your devices allow it.
SMS / WhatsApp · backup only
Better than nothing, but vulnerable to SIM-swap attacks and delivery delays. Keep it as a fallback method, not the primary.
Instagram accounts are stolen with passwords. 2FA breaks the trade.
Hijacked Instagram accounts are a commodity — phished through fake login pages, harvested by “free followers” apps, or bought from old data leaks. Every one of those attacks delivers the same thing: a password. With 2FA on, that password is worthless without your phone, which is why enabling it is the single highest-value security action an Instagram user can take. Pair it with a fresh, unique password and the account is effectively closed to remote takeover.
The one attack 2FA doesn't stop
Real-time phishing: a fake login page that asks for your password and then your 2FA code, relaying both instantly. The defense is procedural — codes go into instagram.com and the app, nowhere else, never into a DM. Instagram staff never ask for codes, and neither does any legitimate service. That includes follower tools: an honest tracker like our unfollowers tracker works from public data and never asks for your password, your code, or your login at all.
The rest of account hygiene
While you're in the security settings: review “Where you're logged in” and evict unknown sessions, check which third-party apps hold access, and save those backup codes. Bigger account moves have their own guides — changing your username, taking a break, or leaving entirely.
2FA, answered
How do I turn on two-factor authentication on Instagram?
Settings and privacy → Accounts Center → Password and security → Two-factor authentication → choose your account → pick a method. An authenticator app is the recommended option; SMS works but is weaker. Setup takes about two minutes.
Which 2FA method should I choose?
Authenticator app (Google Authenticator, Authy, 1Password, etc.) — codes are generated on your device and can't be intercepted like SMS. Add WhatsApp or SMS as a backup only. Instagram also supports passkeys on modern phones, which are even simpler.
What are backup codes and where do I find them?
Five single-use codes that get you in if you lose your phone. They're under Two-factor authentication → Additional methods → Backup codes. Screenshot them and store them somewhere that isn't the phone they're rescuing you from.
I lost my phone — how do I get into my account?
Use a backup code, or log in from a device where you're still signed in and change the 2FA method. Failing both, tap 'Try another way' on the 2FA screen for Instagram's recovery flow. This is exactly the scenario backup codes exist for.
Does 2FA stop phishing?
It stops most of it: a phished password alone can no longer open your account. Sophisticated phishing that asks for your code in real time can still succeed — so never type a code into a site that isn't instagram.com, and never share one in DMs. Instagram staff never ask for codes.
Do I have to enter a code every time I log in?
No — only on new devices or after logging out. Trusted devices you've verified once don't re-prompt, so daily use feels exactly the same.
Secure account. Now grow it safely.
UnfollowCheck tracks your followers and unfollowers from public data — no password, no code, no access to your account. Security-first by design.