I just saw in a year-end report that there is a badge for " Security Conscious" listing users who have authorized two-factored authentication.
It seems strange to me that individual user’s security practices (or lack thereof) would be advertised like this. I understand the whole gamification paradigm to try to get user’s to do things.
I don’t know if knowing that a user doesn’t have 2FA on their account could help with hacking them, but it does seem odd to advertise it.