New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

Key points
- iAuthFlow V2 is a phishing toolkit, meaning a ready-made package criminals use to steal account access at scale.
- The toolkit can register an attacker-controlled passkey inside a victim's account during a phishing session.
- Changing the account password and revoking active sessions does not remove the planted passkey.
- Passkeys are normally considered stronger than passwords, making this abuse particularly unexpected for users and IT teams alike.
- No specific victim count or breach notification has been published at this stage.
Passkeys were supposed to be the password killer. The idea is simple: instead of typing a secret word, your device holds a cryptographic key, a kind of unforgeable digital identity card, and proves who you are automatically. Banks, tech giants, and governments have spent three years telling people to switch. iAuthFlow V2 shows how criminals are already working around that advice.
Researchers revealed this week, first reported by SecurityWeek, that iAuthFlow V2 can do something quietly devastating. When a victim clicks a fake login page and completes what looks like a normal sign-in, the toolkit uses that brief moment of authenticated access to register a new passkey tied to a device the attacker controls. The victim sees nothing unusual.
Why does changing your password not fix this?
Because a passkey is separate from a password. Once the criminal's passkey is registered, the account treats their device as a trusted, verified owner. Resetting your password removes the password. It does not remove the passkey. Even revoking all active login sessions, the standard IT advice after a suspected breach, leaves the planted passkey in place.
That persistence is the point. Standard incident response steps become useless against an attacker who has already registered their own credential inside the account.
What kind of accounts are at risk?
Any platform that supports passkey registration and does not separately audit or alert on new passkey additions. That covers a wide range of consumer and business accounts including email services, cloud storage, and corporate single sign-on systems, where one login grants access to dozens of internal tools.
The attack still requires the victim to visit a fake login page and complete the authentication flow. Phishing, where criminals send convincing fake emails or messages to trick people into logging in on a site they control, remains the entry point. The toolkit does not bypass that step. What it changes is what happens after.
What should affected users and IT teams do?
Four practical steps are worth taking now.
First, check your account security settings and look for a section listing registered passkeys or trusted devices. Delete anything you do not recognise. Second, if your employer manages your accounts, ask the IT or security team whether passkey registrations trigger alerts. If they do not, that is a gap worth closing.
Third, treat unexpected password-reset emails or login notifications as a potential sign that someone is already inside the account, not just knocking at the door. Fourth, be sceptical of any login page you reached through an email link, even one that looks exactly right. Go to services directly by typing the address yourself.
Regulatory jurisdiction over identity-theft incidents of this type sits with the FTC (Federal Trade Commission) in the United States and the ICO (Information Commissioner's Office) in the United Kingdom, among others, though no formal filings have been reported at this stage.



