Two-factor authentication (2FA) was invented to add an extra layer of security to the simple login procedure of entering a username and password. Criminals bypass it by already being in possession of a factor of authentication, or they use that one evil tool that no technology can protect against: social engineering. Most of these methods still need to be made trustworthy enough for everyday use, though industries for which security is imperative have started adopting them, including healthcare institutions, banks, and mobile phones.”]
Source: https://blog.malwarebytes.com/101/2018/09/two-factor-authentication-2fa-secure-seems/