---
title: 'Recommended: enable multi-factor authentication on GARNET accounts'
summary: >-
  As phishing activity against the community increases, GARNET CSIRT strongly
  recommends enabling multi-factor authentication (MFA) on all accounts that
  support it. This advisory explains why and how.
severity: info
status: active
advisoryId: GARNET-CSIRT-2026-003
published: 2026-07-20
affected:
  - 'All garnet.edu.gh account holders'
tags:
  - mfa
  - account-security
  - guidance
tlp: CLEAR
references:
  - title: 'More than a password (CISA)'
    url: 'https://www.cisa.gov/MFA'
---

## Why this matters

Most account compromises we handle start with a stolen password — through
phishing, reuse across sites, or a data breach elsewhere. **Multi-factor
authentication (MFA)** adds a second check (an app prompt, security key, or
one-time code) so a stolen password alone is not enough to sign in.

## Recommended actions

1. **Turn on MFA** for your GARNET email and any service that offers it.
   Prefer an authenticator app or a hardware security key over SMS codes where
   possible.
2. **Register a backup method** (a second device or recovery codes) so you are
   not locked out if you lose your phone.
3. **Use a unique password** per service — a password manager makes this
   practical.

## Need help?

If you are unsure how to enable MFA on a specific service, or you manage a
system for the community and want to require MFA, [contact the team](/contact/).
This advisory is informational — there is no active threat tied to it, but
acting on it meaningfully reduces your risk.
