TL;DR: Gen Z is the most susceptible demographic to phishing, with 62% reporting a scam encounter in the past year, according to Yubico, and the article argues that accessible phishing-resistant authentication and hands-on education are needed to close the digital safety gap. That matters because identity programmes fail when stronger controls remain unavailable to the users most likely to be targeted.
NHIMG editorial — based on content published by Yubico: a youth-focused partnership and phishing-resistant authentication rollout
By the numbers:
- 62% of Gen Z respondents reported engagement with a scam in the past year.
- Yubico is providing nearly 600 free keys to nearly 30 Teen Tech Centers across the U.S.
Questions worth separating out
Q: How should security teams implement phishing-resistant authentication without hurting adoption?
A: Start with the highest-risk populations and applications, then offer the simplest usable authenticators that still meet your assurance target.
Q: Why do younger users remain vulnerable even when stronger login methods exist?
A: Because security strength and security adoption are not the same thing.
Q: What do teams get wrong about phishing-resistant MFA?
A: They often measure success by the presence of a strong factor instead of the absence of weaker bypasses.
Practitioner guidance
- Expand phishing-resistant authentication to high-risk user groups Prioritise users who are most exposed to phishing, credential stuffing, or account recovery abuse, then remove avoidable enrollment friction so the stronger factor is actually adopted.
- Pair deployment with short hands-on training Use setup guides, demos, and recovery walkthroughs so users learn what a legitimate security-key flow looks like and when a prompt should be treated as suspicious.
- Treat recovery paths as part of the control design Review reset, replacement, and fallback flows for phishing resistance so a secure login method is not undermined by weak account recovery.
What's in the full article
Yubico's full article covers the practical rollout detail this post intentionally leaves for the source:
- How the Secure it Forward program is structured across Teen Tech Centers and community partners
- The setup and demo guides used to teach phishing-resistant security keys in a youth-friendly format
- Details of the educational materials created for adult coordinators and teens
- The expansion plan for reaching additional Teen Tech Centers in 2026
👉 Read Yubico's article on phishing-resistant keys and youth digital safety →
Gen Z phishing risk and phishing-resistant keys: what teams should act on?
Explore further
Phishing-resistant authentication only works at scale when access and comprehension move together. The article's core lesson is not just that hardware keys are stronger than passwords, but that controls lose value when only a narrow slice of users can obtain and understand them. In practice, identity security fails when cryptographic strength is treated as sufficient without adoption support. Practitioners should treat usability and availability as part of the control plane, not as afterthoughts.
Identity teams should read this as a broader adoption lesson: strong controls fail when they are not packaged with usable onboarding, recovery, and support. That is true for phishing-resistant authentication today and will be true for other high-assurance identity controls tomorrow. A control that is theoretically superior but operationally inaccessible still leaves the organisation exposed.
A question worth separating out:
Q: How can organisations tell whether authentication is actually phishing-resistant?
A: Authentication is phishing-resistant when a stolen code, password, or proxy cannot be reused to satisfy the login flow. The control should bind the credential to the device or verifier, remove shared secrets from the critical path, and avoid fallback steps that reintroduce phishable factors.
👉 Read our full editorial: Phishing-resistant keys for teens highlight the Gen Z identity gap