Passkeys Under Attack: What the Breach of "Phishing-Proof" MFA Teaches Us
August 10, 2026 · 4 min read · Intelliway Team

For years, passkeys were presented as the definitive solution to the most persistent problem in corporate security: credential theft through phishing. The promise was simple and seductive: no reusable password, nothing for the user to type, no social engineering surface. But recent research, published almost simultaneously, showed that this promise had important fine print, and it changes how security teams should think about authentication in 2026.
What passkeys promised
Passkeys use asymmetric cryptography: a public and private key pair replaces the password. The private key never leaves the device (or the user's synced ecosystem), and the login process requires cryptographic proof that, in theory, cannot be phished because there's no shared secret to steal by typing it into a fake website. Banks, big tech companies, and regulators pushed adoption as a response to the exhaustion of strong password policies and the recurring failure of SMS-based and OTP code MFA.
The problem is that "phishing-resistant" never meant "invulnerable." And that distinction is exactly what three independent lines of research explored, each through a different path, without needing to break the underlying cryptography.
Three ways to bypass without breaking the math
The recent attacks didn't target the cryptographic algorithm behind passkeys, that remains solid. They targeted what surrounds it:
- Reuse of signed authentication material: one vector exploited how Windows exposed already-signed authentication data, allowing an attacker to reuse that proof in contexts that shouldn't have accepted it.
- Abuse of cloud sync: passkeys synced across devices (for user convenience) depend on a cloud system that becomes a target in itself. With malware already present on the victim's machine, it was possible to extract synced private keys, a scenario where endpoint compromise nullifies the authentication protection.
- Bypass of the verification flow: the third line exploited implementation flaws in the checking process, bypassing the barrier without ever interacting with the private key itself.
The common pattern is revealing: no attack broke the cryptography. All of them exploited the implementation layer, sync mechanism, or a compromised endpoint, exactly the points that fall outside the scope when a company adopts passkeys thinking it has "solved" authentication.
Why this matters for security decision-makers in Brazil
There's a dangerous tendency in corporate security: treating strong controls as substitutes for monitoring, rather than as layers that complement it. Passkeys drastically reduce the risk of classic credential phishing, that's real and measurable. But reducing one vector doesn't eliminate the need to detect anomalous behavior after authentication.
If an endpoint is already compromised by malware, as one of the attack vectors showed, the strongest passkey in the world won't stop an attacker from acting within the user's legitimate session. The access control worked perfectly, and compromise still happened. This is exactly the type of scenario where continuous visibility makes the difference between an incident contained in minutes and an attacker with weeks of silent access.
This is where an AI-Driven 24/7 SOC changes the outcome. Not because it replaces strong authentication, but because it assumes authentication will fail somewhere along the chain, whether through a compromised endpoint or an implementation flaw no one tested. A SOC operating with AI agents, like ISA Cyber, can correlate post-login behavioral signals, such as unusual session usage, lateral movement, and token exfiltration, and act before the damage spreads, regardless of whether the attacker walked through the front door with a valid or stolen passkey.
What to do with this information, in practice
For security and IT teams, three concrete actions follow from these findings:
- Don't treat MFA/passkeys as the final control: audit your identity provider's cloud sync flows and understand exactly where the private key actually resides and travels.
- Strengthen endpoint protection: if the device is compromised, a synced passkey becomes just as vulnerable as a password saved in the browser. This raises the priority of EDR and endpoint incident response.
- Map exposure in authentication implementations across your systems: implementation flaws (not protocol flaws) are exactly the kind of finding that shows up in well-executed offensive assessments. A continuous pentest and Red Team program, like the one offered by ISA Horizon, is the most direct way to discover these gaps before an attacker finds them first.
It's also worth continuously reviewing the vulnerability inventory tied to identity and SSO systems across the organization. Vulnerability management performed by VOC with ISA Insight helps prioritize these critical identity assets within the overall volume of findings, something that often gets lost in generic CVE reports.
Conclusion
The core lesson isn't to abandon passkeys, they remain, today, the best available defense against traditional credential phishing. The lesson is to resist the temptation to treat any authentication control, no matter how modern, as sufficient on its own. Mature security assumes failure at every layer and builds detection and response for the moment it happens. Passkeys reduce the probability of initial compromise; SOC, threat intelligence, and continuous pentesting ensure that when the inevitable happens, the organization notices and reacts fast.
Want to assess whether your authentication and monitoring strategy is prepared for this type of attack? Talk to Intelliway at /empresa#contato.
