#Passkeys
15 stories taggedPasskeys.

UK Account Hijacking Fraud Up 400% as Scammers Sell Fake Tickets Through Victims' Own Profiles
Criminals are breaking into people's email and social media accounts to impersonate them, then selling counterfeit concert tickets to the victim's own friends. The UK's cybersecurity authority says one fix is already in most people's pockets.

Microsoft is switching off text-message logins for work accounts in February 2027
Entra ID admins have 15 months to move staff onto passkeys or hardware keys before SMS sign-in stops working.

Fake IT helpdesk calls are opening the door to Microsoft 365 accounts
Microsoft says attackers are ringing staff on personal phones, walking them through passkey 'updates', then pulling SharePoint and OneDrive files.

The Most Common Password Is Still 123456. Here Is What Actually Fixes That.
A former CISO at Hyatt and United Airlines says the security industry keeps chasing new tools while ignoring the basics. One basic above all others stands out: multi-factor authentication, which cuts your chance of being hacked by 99 percent.

N0va phishing kit hunts logins across US and EU businesses
A phishing toolkit called N0va is tricking staff into handing over working accounts, then quietly walking through the front door.

Passkeys Aren't Magic: Researchers Map 39 Ways to Sidestep Them
A new catalogue from Token shows attackers don't need to break the cryptography behind passkeys to steal accounts. They just walk around it.

Microsoft Makes Passkeys the Default Login for Business Accounts. Passwords Aren't Dead Yet.
From September 2026, Microsoft's business identity system defaults to passkeys instead of passwords. But the shift will take years, and most companies will run both systems side by side for a long time.

WhatsApp Rolls Out Alphanumeric Passwords and Multi-Device Passkeys
The messaging app is closing off the easy ways scammers hijack accounts, from '123456' PINs to unknown callers pushing you into a snap decision.

New Phishing Toolkit Registers Attacker Passkeys to Survive Password Resets
A tool called iAuthFlow V2 lets criminals plant a login credential they control inside your account, so changing your password does nothing to lock them out.

Passkeys Aren't Bulletproof: Three New Attacks Sidestep the 'Phishing-Proof' Login
Researchers show how signed login material, malware on synced devices, and clever redirection can defeat passkeys without cracking a single key.

Malware Can Silently Hijack Chrome Passkeys, Researchers Show
Palo Alto's Unit 42 details three attack paths against Google Password Manager that let ordinary user-level malware sign in without a fingerprint, PIN, or on-screen prompt.

Microsoft's New Passkey System Has Flaws That Let Old Hacking Tricks Work Again
A security researcher found three near-exploitable bugs in Windows 11 and Microsoft's cloud login service, just as the company prepares to make passkeys the default sign-in method for hundreds of millions of users.

Microsoft is killing SMS logins for business accounts. Passkeys take over in September 2026.
Entra ID, the sign-in system used by millions of companies, will switch to passkeys by default. Text-message codes get shut off in February 2027.

Criminals Are Calling Your Staff and Stealing Microsoft 365 Logins in Real Time
A hacking group is phoning employees, sending them to fake Microsoft Entra ID login pages, and quietly registering their own passkeys before anyone notices. Okta has the details.

Passkeys Are Winning the Login Fight. Attackers Are Moving to the Verification Step.
Credential stuffing is fading as passkeys go mainstream. The next account takeover battle is happening at password resets, help desks, and identity checks.