Passkeys Are Winning the Login Fight. Attackers Are Moving to the Verification Step.
Credential stuffing is fading as passkeys go mainstream. The next account takeover battle is happening at password resets, help desks, and identity checks.

Key points
- Passkeys, a login method backed by Apple and Google that replaces passwords with a cryptographic key, have gone mainstream in 2025, making bulk credential-stuffing attacks far less profitable.
- Attackers are shifting focus from the login screen to account recovery flows, where a phone call or an SMS code can still hand over an account.
- Account takeover, known as ATO, is the industry term for a criminal gaining control of someone else's online account.
- Defenders who spent a decade hardening logins now have to harden the help desk, the password reset flow, and the identity check behind them.
For about ten years, breaking into online accounts followed a boring recipe. Criminals bought huge lists of stolen usernames and passwords, fed them into automated tools, and waited for matches. This is credential stuffing: throwing known passwords at millions of login pages to see which ones open. Cheap. It scaled. And for security teams on the other side, it was at least a familiar problem.
That era's ending. Not because the criminals lost interest, but because the front door finally got harder to kick in.
A passkey replaces the password with a cryptographic key stored on your phone or laptop, unlocked with your face or fingerprint. There's nothing for a criminal to guess and nothing useful to steal from a breached database. Apple, Google and Microsoft have pushed passkeys into consumer products, and major banks, retailers and workplace tools have followed. The practical effect: stuffing a million stolen passwords into a login page produces far fewer wins than it did two years ago.
So the attackers are moving.
Where are the criminals attacking now?
They're attacking the verification step, the part of an account that handles "I forgot my password" or "I got a new phone."
Every account has one. Real users lose devices, change numbers, and get locked out, so every service builds a back route: call the help desk, receive a code by text, answer a security question, upload a photo ID. That back route is now the softest part of the system.
The pattern, as laid out in reporting by The Hacker News, is straightforward. Criminals no longer need your password if they can convince a support agent, or an automated recovery flow, that they are you. A well-rehearsed phone call to a help desk. A SIM swap, where a mobile carrier is tricked into moving your number to the attacker's SIM card. A forged driver's licence uploaded to an identity-check vendor. Any of these can hand over an account that a passkey was supposed to protect.
This isn't theoretical. Some of the biggest breaches of the past two years, including intrusions at hotel chains and casinos, started with a phone call to IT support, not a cracked password. Our 8 July story on fake DoorDash support calls draining drivers' accounts shows the same mechanic playing out at consumer scale.
What does this mean for ordinary people?
For customers, the login screen is safer than it's been in years. Turn on passkeys wherever your bank or email provider offers them.
But watch the recovery channels. If you get an unexpected text saying your phone number is being moved, or an email confirming a password reset you didn't request, treat it as an emergency. Call the company on a number from its official website, not one from the message.
For companies, the work has shifted. The help desk is not solved the way the login page mostly is. Support agents need scripts that assume the caller may be lying. Identity-verification vendors need testing against deepfake IDs and AI-generated selfies, cheap to produce in 2025. Password reset flows need the same paranoia that login flows got a decade ago.
The bigger story here isn't that passkeys failed. It's that any time a control gets strong enough, attackers route around it. The verification step is where that routing is happening now, and most help desks weren't built to be the last line of defence.



