Skip to main content

Two-Factor Authentication (2FA)

Marine Melamed avatar
Written by Marine Melamed
Updated this week

Overview

To strengthen account security and reduce the risk of unauthorized access, Lusha has introduced mandatory two-factor authentication (2FA) for all paid users (Self-Serve and Enterprise) who sign in with email and password.

Each time you log in, you’ll be asked to enter a one-time 6-digit code sent to your email.

This update helps prevent credential-based attacks, misuse of credits, and unauthorized upgrades—while ensuring a smooth experience for legitimate users.

💡 Note: This update does not apply to users logging in via SSO (Google, Microsoft, Okta, Azure, or Custom SAML).

Use Cases

This feature is especially important for:

  • Protecting against credential leaks: If your password is compromised, a second factor is now required to access your account.

  • Preventing credit abuse: Attackers can no longer consume credits or upgrade plans without your knowledge.

  • Alerting users to suspicious logins: If someone tries to log in, you’ll receive the one-time code and know instantly.

  • Reducing security-related support issues: Helps avoid unnecessary frustration or time spent recovering accounts.

How It Works

  1. Login
    Enter your email and password as usual.

  2. Get a Code
    A 6-digit code is sent to your registered email.
    The code is valid for 10 minutes.

  3. Enter the Code
    Input the code to complete your login.

Session Duration

To stay logged in for 30 days, adjust your Inactivity Timeout settings:

  1. On your Lusha Dashboard, click the Settings icon in the top-right corner.

  2. Go to the Account Settings tab.

  3. Set the Inactivity Timeout to 30 days.

You’ll stay logged in for up to 30 days, unless:

  • You log out manually

  • You switch browsers or devices

  • You use incognito mode

If an Unauthorized Attempt Occurs

  • The attacker will not receive the code, and therefore cannot log in.

  • You will receive the code, which acts as a warning that someone tried to access your account.

  • We recommend updating your password immediately in this case.

Did this answer your question?