As awareness grows around many MFA methods being “phishable” (i.e. not phishing resistant), passwordless, FIDO2-based authentication methods (aka. passkeys) like YubiKeys, Okta FastPass, and Windows Hello are being increasingly advocated. This is a good thing. The most commonly used MFA factors (like SMS codes, push notifications, and app-based OTP) are routinely bypassed, with modern reverse-proxy “Attacker-in-the-Middle” phishing kits the most common method (and the standard choice for phishing attacks today). These work by intercepting the authenticated session created when a victim enters their password and completes an MFA check. To do this, the phishing website simply passes messages between the user and the real website — hence “Attacker-in-the-Middle”. In contrast, passkey-based logins can’t be phished. Because passkey-based logins are domain-bound, trying to use a passkey for microsoft.com on phishing.com simply won’t generate the correct value to pass the authentication check, even when proxied using an AitM kit. But attackers haven’t given up that easily. As passkeys become more popular, we’re seeing a number of techniques designed to downgrade or otherwise circumvent the authentication process to make it vulnerable to phishing attacks. So, here’s all the techniques that attackers have used to get around passkeys (so far). Downgrade attacks are the go-to method used by attackers to get around phishing-resistant MFA. MFA downgrade functionality has been observed in...
How attackers are still phishing "phishing-resistant" authentication
BleepingComputer
·Sponsored by Push Security
·Published Jul 29, 2025
·Updated
Affected Software
3 affected components
Microsoft Windows Hello
Okta Okta FastPass
Yubico YubiKeys
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses how attackers are circumventing phishing-resistant authentication methods such as passwordless and FIDO2-based systems.
2
What security implications are discussed?
The article highlights the ongoing risks of phishing, even against advanced authentication methods that are designed to be resistant.
3
What products or software are affected?
The affected products include YubiKeys, Okta FastPass, and Microsoft Windows Hello.
4
What are phishing-resistant authentication methods mentioned?
Phishing-resistant authentication methods mentioned include passwordless systems and FIDO2-based authentication like passkeys.
5
Why is phishing still a concern with advanced authentication methods?
Phishing remains a concern because attackers continuously adapt their techniques to exploit vulnerabilities in even the most secure authentication methods.