New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

Key points
- IAuthFlow V2 is a phishing toolkit, meaning a ready-made package criminals use to steal account access at scale.
- The toolkit can register an attacker-controlled passkey inside a victim's account during a phishing session.
- Changing the account password and revoking active sessions does not remove the planted passkey.
- Passkeys are normally considered stronger than passwords, making this abuse particularly unexpected for users and IT teams.
- No specific victim count or breach notification has been published at this stage.
Passkeys were supposed to kill the password. Instead of typing a secret word, your device holds a cryptographic key, a kind of unforgeable digital identity card, and proves who you are automatically. Banks and tech giants have spent three years telling people to switch. IAuthFlow V2 shows how criminals are already working around that advice.
Researchers revealed this week, first reported by SecurityWeek, that iAuthFlow V2 can do something quietly devastating. When a victim clicks a fake login page and completes what looks like a normal sign-in, the toolkit uses that brief moment of authenticated access to register a new passkey tied to a device the attacker controls. The victim sees nothing unusual. Our August reporting found passkeys under pressure from several angles: malware targeting Chrome's passkey store on 3 August and, a week later, three separate attack paths that sidestep the "phishing-proof" label. IAuthFlow V2 is a different threat: it doesn't crack a passkey, it simply adds one.
Why does changing your password not fix this?
Because a passkey is separate from a password. Once the criminal's passkey is registered, the account treats their device as a trusted, verified owner. Resetting your password removes the password. It doesn't remove the passkey. Even revoking all active login sessions, the standard IT advice after a suspected breach, leaves the planted passkey in place.
That persistence is the point. Standard incident response becomes useless against an attacker who has already registered their own credential inside the account.
What kind of accounts are at risk?
Any platform that supports passkey registration and doesn't separately audit or alert on new passkey additions. That covers consumer and business accounts alike: email services, cloud storage, corporate single sign-on systems where one login grants access to dozens of internal tools.
The attack still requires the victim to visit a fake login page and complete the authentication flow. Phishing, where criminals send convincing fake emails or messages to trick people into logging in on a site they control, remains the entry point. What iAuthFlow V2 changes is what happens after.
What should affected users and IT teams do?
Four practical steps are worth taking now.
First, check your account security settings and look for a section listing registered passkeys or trusted devices. Delete anything you don't recognise. Second, ask your IT or security team whether passkey registrations trigger alerts. If they don't, that's a gap worth closing.
Third, treat unexpected password-reset emails or login notifications as a potential sign that someone is already inside the account, not just knocking at the door. Fourth, be sceptical of any login page you reached through an email link, even one that looks exactly right. Go to services directly by typing the address yourself.
Regulatory jurisdiction over identity-theft incidents of this type sits with the FTC (Federal Trade Commission) in the United States and the ICO (Information Commissioner's Office) in the United Kingdom, though no formal filings have been reported at this stage.



