Short answer: it's a second lock on your account. Even with your stolen password in hand, a scammer still can't get in without the code on your phone.
Passwords leak. They get phished, guessed, or exposed in a data breach on some other website you barely remember using. Once a scammer has your password, a normal account has nothing left standing between them and everything in it. Two-step verification, often shortened to 2FA, closes that gap by requiring a second piece of proof, usually a code sent to your phone, before anyone can log in.
Think of it as a deadbolt on top of your regular door lock. Takes about five minutes to set up. Stops most takeovers cold.
Look at which apps have access to your Google or Facebook account, under "Third-party apps with account access." Remove anything you don't recognize, each unknown connection is a potential way in that has nothing to do with your password at all.
Also check which devices are currently logged into your accounts. Gmail, Facebook, and WhatsApp all let you see this directly. If you spot a device or location you don't recognize, remove it and change your password immediately.
This is one trick out of dozens. The Scam-Proof Playbook covers passwords, Gmail security, WhatsApp scams, and more, in plain language, with real examples.