Account protection
When an attacker knows a password, 2FA still requires access to the enrolled email account, authenticator or recovery code. This blocks many automated and password-reuse attacks.
Stolen passwordNot enough by itself.
Unexpected codes warn youSomeone may be trying to sign in.
Layered securityProtect every factor.
Threats reduced
A leaked password from another site cannot normally complete a UKC login without the second factor. Use a unique password anyway so the first layer remains strong.
Warning signs
Do not enter or forward it. Change the password from the genuine UKC site, review the email account's security and contact support if account activity looks unfamiliar.
Complete the protection
Email 2FA depends on the mailbox remaining secure. TOTP and email codes can still be captured by a convincing real-time fake login page, so always verify the address before entering them.
Article feedback