Skip to main content

The Money Overview

Social Security now requires a second security step to log in online, and users who don’t set it up can be locked out of the account that guards their benefits

The Social Security Administration cut off its own username-and-password login system, and anyone who has not set up a second verification step through a third-party provider now risks losing online access to benefit statements, payment records, and account changes. The shift, which took full effect on June 7, 2025, funnels all users through Login.gov or ID.me, both of which demand multi-factor authentication on top of a standard password. For beneficiaries who struggle with the extra step or lose their authentication device, the path back in can mean deleting an account entirely and starting from scratch.

Why the login change puts beneficiaries at real risk of lockout

The SSA removed the option to sign in with a Social Security username and password. Login.gov and ID.me are now the only doors into my Social Security online services. Both require users to verify their identity with something beyond a password each time they sign in. Login.gov lists several accepted methods, including an authentication app on a smartphone, a physical security key, and one-time backup codes.

The practical danger sits in what happens when that second factor breaks. A lost phone, a wiped device, or a forgotten backup code can strand someone outside the system. Login.gov’s own guidance on how to add or change authentication methods notes that people without a working second factor may have to remove and re-establish their login. In some cases, users who lose all access to their authentication tools and have no backup connected may need to delete their Login.gov account and create a new one. That process severs the link to the my Social Security profile, forcing the user to re-verify identity from the beginning. During that gap, a beneficiary cannot check payment status, request a replacement Social Security card, or update direct deposit details online.

The hypothesis that this credential shift will drive a measurable rise in duplicate or abandoned accounts among older users within six months of full enforcement is plausible but unproven. The SSA has not published data on how many existing my Social Security users have migrated to Login.gov or ID.me, and no public figures exist on lockout incidents or recovery success rates since the June 2025 cutover. Without that data, the scale of disruption remains an open question, even as the structural conditions for it are clearly in place.

How the SSA shifted accountability to a third-party credential provider

The agency framed the move as an alignment with federal authentication standards designed to improve security. That rationale tracks with broader government efforts to standardize identity verification across agencies. Stronger login requirements are meant to reduce account takeovers and fraud, particularly for high-value benefits like Social Security retirement and disability payments.

But the same decision also means the SSA no longer manages the front door to its own services. When users run into trouble logging in, the agency’s FAQ directs them away from Social Security and toward the Login.gov help center and phone support. In effect, a beneficiary locked out of their benefits is not calling Social Security about a Social Security problem; they are calling another federal agency about a credential that also unlocks dozens of unrelated programs.

That handoff has practical consequences. Support agents at Login.gov are trained to resolve identity-proofing and multi-factor authentication issues, not to answer questions about benefit overpayments or Medicare enrollment. A person who cannot sign in may end up bouncing between two agencies: one that controls the login and one that controls the benefits. The SSA has tried to mitigate some of this friction by adding a Security Authentication PIN, or SAP, for my Social Security accountholders beginning in August 2025. The PIN is meant to speed up identity checks when people call the National 800 Number, but it does not replace or bypass the online login requirement.

What beneficiaries still do not know about account recovery

The least understood part of the new system is what happens when something goes wrong. The SSA’s public materials describe how to create an online account and encourage users to choose strong passwords and keep contact information current. They are far less explicit about worst-case scenarios: a stolen phone that held the only authentication app, an email account that can no longer be reached, or backup codes printed years ago and misplaced.

Login.gov’s documentation does outline ways to reconnect a second factor, such as using backup codes, switching to a different device, or adding a new authentication method while the old one still works. Yet many beneficiaries never see these instructions until after they are already locked out. For older users, people with limited English proficiency, or those without a smartphone, the idea of managing multiple factors, codes, and devices can be confusing enough that they avoid setting up backups altogether.

In that environment, the burden of resilience shifts almost entirely onto the individual. Beneficiaries must not only remember a password but also maintain at least one reliable second factor and, ideally, a backup method. They need to store recovery codes somewhere safe yet accessible and update their login settings when they change phones or email addresses. If they do not, they may discover during a crisis-a missing payment, a suspected fraud incident-that the fastest way to fix the problem is no longer available to them online.

For now, the gap between the security model on paper and the lived experience of beneficiaries remains largely undocumented. Until the SSA or Login.gov publish clear data on lockouts, recovery times, and support outcomes, the risks will be measured one frustrated caller at a time, trying to regain access to benefits that depend on a login they no longer control.

Free for readers: The free Retirement Shield newsletter sends plain-English help keeping more of your money in retirement — the scams to dodge, the benefits you’re owed, and what’s changing with Social Security and Medicare, a couple times a week. Get the free newsletter.

Avatar photo

Daniel Harper

Daniel is a finance writer covering personal finance topics including budgeting, credit, and beginner investing. He began his career contributing to his Substack, where he covered consumer finance trends and practical money topics for everyday readers. Since then, he has written for a range of personal finance blogs and fintech platforms, focusing on clear, straightforward content that helps readers make more informed financial decisions.​


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.