When a user connects to your service, you ask him an additional code. This code will be generated simultaneously on your server and on the user's mobile. Both codes will be compared to guaranteed a secured access. You can add a mechanism against the brute force to increase security.
With OOTFY, even if a password stolen your users are safe. An analysis of server's logs may detect intrusion attempt.