Security News

New Phishing Toolkit Turns Passkeys Against You—Even After You Reset Your Password

Security Week · 22 Aug 2026
Key Takeaway Regularly audit and remove unfamiliar passkeys or devices linked to your business accounts, since simply changing your password may not be enough to remove an attacker's access.

Security researchers have uncovered a phishing toolkit, dubbed iAuthFlow V2, that exploits passkeys—a modern login method designed to be more secure than passwords—to maintain long-term access to compromised accounts. Once attackers trick a victim into using the toolkit, they can register their own passkey on the account without the victim's knowledge.

This is particularly concerning because passkeys are often marketed as a safer alternative to passwords, resistant to typical phishing attacks. However, this toolkit shows that if an account is compromised at the point of passkey registration, the attacker can retain access even if the victim later changes their password or logs out of all active sessions—actions that would normally lock out an intruder.

For small businesses, this highlights a growing risk in account security: strong authentication methods can still be undermined by social engineering and toolkits designed to exploit them. Businesses relying on passkeys should ensure they regularly review which devices and credentials are registered to important accounts, not just assume that resetting a password is enough to remove unauthorised access.

phishing passkeys account security

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.