Cybersecurity · Threat Landscape · Passkeys series, Part 3 of 5

Which attacks do passkeys stop? Phishing, credential stuffing, breaches and replay

Written by the Mono training team · · 9 min read Share
Executive summary Most security controls make an attack harder. Passkeys do something rarer: for four whole classes of attack, they remove the thing the attack depends on. Credential phishing, credential stuffing, password database theft and replay all rely on a reusable secret travelling or being stored somewhere it can be copied. Passkeys have no such secret. This article takes each attack in turn, shows how it works against passwords and one-time codes, and marks exactly where it breaks once passkeys are in place. It closes with the places where that protection is less absolute than it sounds, which is where Part 4 begins.
Data sources
Microsoft Threat Intelligence (2022, 2024)·CISA, Implementing Phishing-Resistant MFA (2022)·CISA and FBI advisory AA23-320A (updated 2025)·W3C Web Authentication Level 3·Proofpoint Threat Research (2025)·UK NCSC (April 2026)
Reflects published research and advisories as of September 2026.
01Attack one

Credential phishing: the fake page stops working

Classic phishing collects a password on a look-alike page. The modern version, known as adversary-in-the-middle (AiTM) phishing, goes further: a proxy sits between you and the genuine site, forwarding everything in both directions. You see the real login flow, you complete the real MFA prompt, and the proxy keeps the session cookie the real site issues at the end. Microsoft documented one such campaign that attempted to target more than 10,000 organisations, noting the attacker was authenticated on the user's behalf regardless of the sign-in method, SMS codes and authenticator apps included. In one case, follow-on payment fraud began within five minutes.

Attack 1 · Credential phishing, including real-time proxies
THE LUREemail, text or adFAKE PAGEattacker's proxyREAL SERVICEyour accountATTACKERsigned in as youyou clickand codeyou type passwordrelayed liveACCOUNT TAKEN, CODE AND ALLTHE LUREemail, text or adFAKE PAGEattacker's proxyREAL SERVICEyour accountATTACKERsigned in as youyou clickno signaturenothing to relayNO KEY FOR THIS DOMAIN
Without passkeys. You enter your password and your one-time code on a convincing copy of the login page. A proxy passes both to the real service in real time, so the code is still valid when it arrives. The attacker ends up with your session.With passkeys. The fake page can ask for a passkey, and your browser will pass the request on, but with the fake page's real address attached. Your authenticator holds no key for that domain, so it signs nothing. You do not need to notice anything for this to work.

This is why CISA calls FIDO/WebAuthn the only widely available phishing-resistant authentication. The origin binding described in Part 1 means the signature a proxy would need is never created in the first place.

02Attack two

Credential stuffing and spraying: nothing left to try

Credential stuffing industrialises password reuse: huge lists of email and password pairs from past breaches are replayed automatically against other services. Password spraying flips it around, trying a handful of common passwords against many accounts to avoid lockouts. Neither needs any skill beyond patience and a list.

Spraying is not a low-level problem. Microsoft reported that in late 2023 the Russian state actor it tracks as Midnight Blizzard gained its initial foothold in Microsoft's own corporate environment through a password spray against a legacy test account that did not have MFA enabled.

Attack 2 · Credential stuffing and password spraying
SITE A BREACHaccount recordsATTACKER'S BOTautomated loginsSITE Byour other accountATTACKERin, wherever reusedor soldlist leakedeverywheresame pair triedone worksREUSE TURNS ONE BREACH INTO MANYSITE A BREACHaccount recordsATTACKER'S BOTautomated loginsSITE Byour other accountATTACKERin, wherever reusedkeys leakonly publicnothing to tryone worksNOTHING REUSABLE TO TRY
Without passkeys. Passwords stolen from one service are tried automatically against many others. Password spraying is the mirror image: a few common passwords tried against many accounts. Both only need people to reuse or choose guessable passwords.With passkeys. There is no password to reuse and nothing to guess. Every passkey is unique to one service, and a breach at Site A exposes public keys that cannot sign in anywhere, including at Site A.

With passkeys, both attacks lose their raw material. There is no shared secret to reuse between sites, and no password to guess, because the account can be configured to have no password at all.

03Attack three

Server-side breaches: the stolen table is worthless

When a service is breached, password hashes are among the first things attackers look for. Good hashing slows cracking down; it does not stop it, and it does nothing for passwords that are short, common or reused. The damage from one breach then spreads through every other service where those passwords work.

Attack 3 · Password database theft
THE DATABASEcopied by attackerOFFLINE GUESSINGno lockouts, no alertsLOGIN PAGEsame serviceATTACKERsigned inexfiltratedhashescrackedweak onesvalid passwordEVERY CRACKED HASH IS A WAY INTHE DATABASEcopied by attackerOFFLINE GUESSINGno lockouts, no alertsLOGIN PAGEsame serviceATTACKERsigned inexfiltratedpublic keysnothing to crackvalid passwordPUBLIC KEYS CANNOT SIGN
Without passkeys. A stolen table of password hashes can be attacked offline, at the attacker's own pace, with no lockout and no alert. Every weak or reused password that falls becomes a working login.With passkeys. A passkey service stores public keys. There is nothing to crack: a public key is designed to be published, and it can only check signatures, never produce them.

A breach at a passkey-only service still matters, because customer data, internal documents and sessions can all be stolen. What it no longer yields is a way to sign in as the customers.

04Attack four

Interception and replay: yesterday's answer does not fit today's question

Anything typed can be captured. A keylogger records a password as it is entered; a shoulder-surfer reads it off the screen; a proxy copies a one-time code in transit. All of these rely on the captured value being accepted again.

Attack 4 · Interception and replay
YOU SIGN INpassword or codeCAPTUREDproxy or keyloggerREPLAYEDwhile still validATTACKERsigned insecret typedcopy keptacceptedA COPY IS AS GOOD AS THE ORIGINALYOU SIGN INpassword or codeCAPTUREDproxy or keyloggerREPLAYEDwhile still validATTACKERsigned insignature sentcopy keptacceptedOLD CHALLENGE: REJECTED
Without passkeys. A password never expires on its own, and a one-time code stays valid for a short window. Whoever captures either, by proxy, keylogger or over a shoulder, can use it.With passkeys. The signature answers one specific challenge, bound to one origin. The server issues a new challenge every time, so a captured signature fails the moment it is replayed.

Passkeys also remove several related techniques at once. CISA's advisory on the group known as Scattered Spider describes push-notification fatigue and SIM swapping as standard moves; both lose their purpose when there is no push to approve and no SMS code to intercept.

Push fatigue

Repeated approval prompts until someone taps yes. A passkey needs a local gesture on the right site; there is no remote prompt to approve.

SIM swapping

Hijacking a phone number to receive SMS codes. Passkeys do not use the phone number at all.

Keylogging a password

A keylogger can still capture a PIN, but a passkey PIN only unlocks the authenticator it belongs to. Without the device, it opens nothing.

05The fine print

Where "eliminated" needs an asterisk

All four attacks are structurally eliminated for sign-ins that actually use a passkey. Three conditions can quietly undo that.

  • A fallback is still available. If an account can also sign in with a password, a code or a push approval, an attacker only needs to persuade the person to use that instead. In August 2025 Proofpoint researchers demonstrated a downgrade technique: a phishing proxy pretends to be a browser that does not support passkeys, so the sign-in page offers a weaker method. Proofpoint had not seen it used in the wild, but it shows why the fallback, not the passkey, becomes the target.
  • The synced keychain is weakly protected. As Part 2 explains, a synced passkey is as strong as the account behind it.
  • The attack happens after sign-in. Passkeys protect the moment of authentication. Session cookies, consented apps and malware on the device all operate after that moment.

The first of these comes down to a person at a screen, reading an unexpected message such as "this browser is not supported, try another way". Whether they pause there is the whole defence.

Part 4 · What still worksPasskey weaknesses: the attacks that still work, and how to defend against them→
Key takeaways

What to take into your next risk conversation

01

Phishing pages collect nothing

Origin binding means no signature is ever produced for a look-alike domain, even when the person is completely fooled.

02

Reuse and guessing disappear

Unique keys per service and no password to spray remove credential stuffing and spraying at the root.

03

Breached tables stop being keys

A server that stores only public keys has nothing to crack and nothing to reuse.

04

Remove the fallbacks

The protection only holds where the passkey is the only way in. Every remaining fallback is the new front door.

Next in the series · Part 4 of 5

Passkey weaknesses: the attacks that still work, and how to defend against them

Read Part 4 →
Sources and further reading
  1. Microsoft Threat Intelligence, From cookie theft to BEC: attackers use AiTM phishing sites, July 2022
  2. Microsoft Threat Intelligence, Midnight Blizzard: guidance for responders on nation-state attack, January 2024
  3. CISA, Implementing Phishing-Resistant MFA, October 2022
  4. CISA and FBI, Scattered Spider, advisory AA23-320A, updated July 2025
  5. Proofpoint, Don't phish-let me down: FIDO authentication downgrade, August 2025
  6. W3C, Web Authentication Level 3
  7. UK NCSC, Leave passwords in the past: passkeys are the future, April 2026