TL;DR: AI-powered phishing, with AiTM kits and deepfake lures, is making traditional MFA easier to bypass while FIDO2 and passkeys stop proxy attacks through cryptographic domain binding, according to WorkOS. The real risk is not passkey adoption itself, but leaving SMS, push, email reset, or QR-code fallbacks active, which reopens the attack path.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “Passkeys stop phishing. Your MFA fallbacks undo it.”.
Key questions
Q: What breaks when passkeys are used alongside weak fallback authentication?
A: The programme becomes only as strong as the fallback path.
Q: Why do passkeys still leave organisations exposed to phishing attacks?
A: Passkeys reduce phishing risk only when they are the sole usable method.
Q: How should security teams decide whether QR-based passkey flows are acceptable?
A: They should decide based on the threat model, not convenience.
Practitioner guidance
- Audit the fallback surface Inventory every active authentication and recovery path in each identity provider and application, including SMS, push, email codes, backup codes, password reset, and "try another way" options.
- Make phishing-resistant methods mandatory for privileged users Require passkeys or hardware security keys for administrators, finance roles, and production access, rather than offering them as optional enrollment choices.
- Remove phishable recovery routes Redesign account recovery so it cannot bypass the phishing-resistant method through email or SMS, and require stronger identity proofing or pre-enrolled recovery codes instead.
Bottom line: Passkeys reduce proxy phishing risk, but only when the identity stack stops offering weaker alternate routes.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phishing resistance is a property of the entire authentication chain, not the strongest factor in it. Passkeys stop proxy phishing only when weaker branches are removed, because attackers do not need to defeat the cryptographic method if they can downgrade the session into a recoverable or alternative path. That makes fallback governance part of the control surface, not an implementation detail. Practitioners should judge authentication by the weakest surviving route.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: What is the difference between passkey security and MFA strength?
A: Passkey security is protocol-enforced phishing resistance through cryptographic domain binding. MFA strength is broader and can still include phishable methods such as SMS, push, or email reset. A system can use a strong factor and still be weak overall if it leaves alternate paths that attackers can exploit.
👉 Read our full editorial: Passkeys fail when MFA fallbacks remain in place