Attackers Use Passkey-Themed Phishing to Breach Cloud Environments
KnowBe4, Tuesday, September 15th, 2026
Phishing campaigns exploit passkey enrollment flows to register attacker-controlled authenticators in cloud tenants.
KnowBe4 covers phishing operations that weaponize passkey adoption itself. Attackers send messages prompting users to enroll or re-enroll a passkey, steering them into flows that register an attacker-controlled authenticator on the victim's cloud account.
Because passkeys are marketed as phishing-resistant, users lower their guard during enrollment. The post stresses that enrollment and recovery paths remain the weak point even in strong authentication deployments.