Short answer: Sign in to Payoneer, open Settings → Security Center and enable two-step verification. Choose the authenticator app option rather than SMS if your account offers it, scan the QR code, and confirm with the six-digit code. Then verify your withdrawal bank details, because that is the field an attacker changes first.
Why this account deserves your best security
For a lot of freelancers, Payoneer is where the money actually lands. Marketplace earnings, direct client payments, and the bank transfer out — all flowing through one login.
Two things make it a serious target. It holds a balance, and it holds your withdrawal destination. An attacker who gets in does not need to move money out immediately; they can change the linked bank account and wait for your next payout to arrive in theirs.
There is also a slower, quieter version of the attack: they change your email or add a device, watch your incoming payments, and time an intervention around a large one.
Financial accounts also come with a recovery process that is deliberately slow, for good reasons. Getting locked out is not a five-minute inconvenience — which makes both enabling 2FA and backing it up properly important.
Step 1: Open the Security Center
- Sign in at myaccount.payoneer.com.
- Click the settings or profile icon and choose Settings.
- Open Security Center.
- Find the two-step verification section.
Payoneer’s interface changes periodically and some options vary by region and account type. If labels differ from the above, everything you need is grouped under account security or the security centre.
Step 2: Choose your verification method
Payoneer typically offers verification by SMS, email, or an authenticator app depending on your region and account.
Choose the authenticator app if it is available. Codes are generated offline on your device, so nothing travels through the phone network where a SIM swap could intercept it. This matters especially for freelancers, whose email addresses and phone numbers are often published on portfolios and marketplace profiles — making targeted attacks easier than for an average consumer.
If only SMS is offered, use it. Any second factor is far better than none, and it stops the automated attacks that account for most account compromises — see credential stuffing. Then add a carrier port-out PIN to protect the number itself.
Scan the QR code with any standard authenticator — Google Authenticator, Aegis, 2FAS, Microsoft Authenticator, or a password manager. If you are new to this, start with what is an authenticator app; if the code will not scan, use manual key entry.
Never screenshot the QR code. It contains the raw secret, and screenshots sync to cloud photo libraries.
Step 3: Back it up before you need to
This is more important on a financial account than anywhere else, because self-service recovery is limited by design.
- Save any backup or recovery codes Payoneer provides, offline — see where to store backup codes safely.
- Put the token on a second device while the QR code is on screen. Two devices generating the same codes is the cleanest insurance there is.
- Make sure your authenticator app itself has a working backup — how to back up your authenticator app.
Losing access to a payments account while an invoice is due is a specific and avoidable kind of stress.
Step 4: Check the details that actually move money
Login security is one layer. On a payments platform, these matter just as much:
- Withdrawal bank accounts — confirm every linked account is yours. Delete any you no longer use. Check this again after any suspicious email or login alert.
- Registered email address — it must be current, and it must have strong 2FA of its own. Whoever controls your email can attempt a reset. See our Google and Microsoft guides.
- Phone number — current, and protected with a port-out PIN at your carrier.
- Notification settings — turn on every alert Payoneer offers. Alerts about logins, changed details and withdrawals are your early warning system.
- Linked marketplaces — review which platforms are connected to your account.
The scams aimed specifically at freelancers
These are the ones circulating right now, and 2FA does not stop any of them by itself:
- Fake client onboarding. A “client” sends a form or portal asking you to verify your payment details. It is a credential harvester.
- Payment notification phishing. An email claiming a payment is waiting, with a link to a fake login page. Always go to Payoneer directly rather than clicking.
- Overpayment refunds. A client “accidentally” overpays and asks you to return the difference. The original payment is later reversed.
- Support impersonation. Someone claiming to be Payoneer, asking for your code to “verify your identity”. Payoneer will never ask. See OTP scams.
- Malicious project files. A “brief” or “design asset” that is actually infostealer malware, which takes your session cookies and bypasses login entirely — see session hijacking.
The habit that defeats most of these: never log in through a link. Type the address yourself, every time.
Frequently asked questions
Is 2FA mandatory on Payoneer?
Payoneer applies verification steps to sensitive actions like withdrawals and detail changes regardless. Enabling account-level two-step verification adds protection at login, which is where takeovers begin.
Which authenticator app should I use?
Any standard TOTP app — see how TOTP codes work. Use whichever you already use for other accounts, provided it is backed up.
Why is my code being rejected?
Almost always clock drift on your phone. Turn on automatic network time in date and time settings. More: why 2FA codes get rejected.
What if I lose my phone?
Contact Payoneer support and expect identity verification — financial platforms are deliberately strict. This is precisely why a second device and saved codes matter. See recovering accounts after losing your 2FA phone.
I changed my phone number. What should I do?
Update it in Payoneer before you lose access to the old one, and while your authenticator app still works. Our guide covers the sequence: what happens to your 2FA when you change phone number.
Someone has accessed my account. What now?
Contact Payoneer immediately — speed matters with money in motion. Then change the password, check and correct withdrawal bank details, review recent activity, and check your email account for forwarding rules an attacker may have added.
The bottom line
Enable the strongest verification Payoneer offers you, back it up on a second device the same day, and then check your withdrawal bank details and email security — because on a payments account, the login is the door but the bank field is the safe. Ten minutes, and it protects the account your income actually flows through.
Working across several platforms? Our companion guide covers the wider picture: 2FA for freelancers.