Twitter is about to get less secure for millions of users - here's what you can do

Elon Musk in front of the Twitter logo
(Image credit: Kovop via Shutterstock)

If you've been following the Twitter saga closely, then you will know that today, March 20, is the day that the social media giant is disabling its two-factor authentication (2FA) via SMS feature for those without a subscription to Twitter Blue.

This is bad enough for individual users, but for businesses the danger is even more pronounced, as it means threat actors can breach enterprise accounts with the firm's login credentials alone, allowing them to besmirch the reputation of the brand by writing malicious tweets or impersonating them in acts of identity theft.

Yesterday was the deadline for switching to a different authentication method for 2FA, such as using an authenticator app to generate your authentication codes instead of a text message. If you failed to change in time, then 2FA will be gone forever now unless you sign up and pay for Twitter Blue. But don't worry, as there are still ways to keep your free Twitter account secure.

Twitter blues

First of all, it is worth mentioning that SMS authentication is considered to be one of the least secure methods. SMS texts can be much more easily intercepted by threat actors in acts of Sim swapping, where criminals manage to port your phone number to their own device so they can see every message you receive. 

Even without any form of 2FA or multifactor authentication (MFA) in place, you can still improve your security posture in other ways. Having a strong password is a must - one that avoid obvious phrases such as 'password1234' and the like. You'd be surprised how many prominent businesses still use these

What puts people and business off creating strong passwords, however, is that their complexity makes them hard to remember, especially if you adhere to the other recommended practice of creating a unique password for every account you have. 

This is where password managers come in. They take care of creating and storing your strong passwords for you, so there's no need to commit them to memory. Enterprises will want to take advantage of the features offered by the best business password managers, as these allow for multiple users to safely and securely store and use all the passwords used by your organization.  

Good password managers will also let you know if your credentials have been leaked in any data breach, so if Twitter were to succumb to an attack, then they should let you know and give you the chance to change your password immediately. Although an organization as big as Twitter should let users know directly if they've been affected by a breach. Under Elon Musk's tenure, however, anything is possible it seems.  

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
Security padlock in circuit board, digital encryption concept
MFA alone won’t protect you in 2025: the new cybersecurity imperative
Representational image of a shrouded hacker.
Getting to grips with Adversary-in-the-Middle threats
An abstract image of a lock against a digital background, denoting cybersecurity.
Building a resilient workforce security strategy
Person using finger print authentication
Passwords out, passkeys in: The future of secure authentication
password manager
I'm a security expert - here are my biggest tips for creating a secure password for work and home life to stay safe online
digital key
Microsoft really wants users to ditch passwords and switch to passkeys
Latest in Security
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
Web DDoS attacks see major surge as AI allows more powerful attacks
Polish space agency says it was hit by a cyberattack
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
Latest in News
Google Gemini iPhone Lock Screen
You can now access Gemini from your iPhone's lock screen
Michelle, Keats, and Doctor Amherst looking unimpressed and worried in The Electric State
Netflix drops trailer for The Electric State, and I'm getting serious District 9 vibes
YouTube TV
YouTube TV might be planning a big Netflix update that puts the best streaming services first
Google Pixel 9 Pro
Here are the 7 best Pixel 9 and Pixel Watch 3 features landing in March’s Pixel Feature Drop
Bang & Olufsen Beogram 4000C Saint Laurent Rive Droite Edition
Bang & Olufsen's latest reworked turntable is a masterpiece of retro revival, in a breathtaking wooden presentation box
Apple Watch Series 10
Apple unveils new Apple Watch bands – here's what's in the Spring 2025 collection