• News/
  • https://www.bleepingcomputer.com/news/security/how-attackers-are-still-phishing-phishing-resistant-authentication/

How attackers are still phishing "phishing-resistant" authentication

BleepingComputer
·
Sponsored by Push Security
·
Published Jul 29, 2025
·
Updated

As awareness grows around many MFA methods being “phishable” (i.e. not phishing resistant), passwordless, FIDO2-based authentication methods (aka. passkeys) like YubiKeys, Okta FastPass, and Windows Hello are being increasingly advocated. This is a good thing. The most commonly used MFA factors (like SMS codes, push notifications, and app-based OTP) are routinely bypassed, with modern reverse-proxy “Attacker-in-the-Middle” phishing kits the most common method (and the standard choice for phishing attacks today). These work by intercepting the authenticated session created when a victim enters their password and completes an MFA check. To do this, the phishing website simply passes messages between the user and the real website — hence “Attacker-in-the-Middle”. In contrast, passkey-based logins can’t be phished. Because passkey-based logins are domain-bound, trying to use a passkey for microsoft.com on phishing.com simply won’t generate the correct value to pass the authentication check, even when proxied using an AitM kit. But attackers haven’t given up that easily. As passkeys become more popular, we’re seeing a number of techniques designed to downgrade or otherwise circumvent the authentication process to make it vulnerable to phishing attacks. So, here’s all the techniques that attackers have used to get around passkeys (so far). Downgrade attacks are the go-to method used by attackers to get around phishing-resistant MFA. MFA downgrade functionality has been observed in...

Read full article

Affected Software

3 affected components
Microsoft Windows Hello
Okta Okta FastPass
Yubico YubiKeys
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how attackers are circumventing phishing-resistant authentication methods such as passwordless and FIDO2-based systems.

2

What security implications are discussed?

The article highlights the ongoing risks of phishing, even against advanced authentication methods that are designed to be resistant.

3

What products or software are affected?

The affected products include YubiKeys, Okta FastPass, and Microsoft Windows Hello.

4

What are phishing-resistant authentication methods mentioned?

Phishing-resistant authentication methods mentioned include passwordless systems and FIDO2-based authentication like passkeys.

5

Why is phishing still a concern with advanced authentication methods?

Phishing remains a concern because attackers continuously adapt their techniques to exploit vulnerabilities in even the most secure authentication methods.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
How attackers are still phishing "phishing-resistant" authentication - SecAlerts