Passkeys can resist credential phishing on lookalike websites, including convincing pages promoted through AI-assisted lures. FIDO2 security keys can store the device-bound credentials used for that protection. Passkeys do not, by themselves, prevent malicious authorization requests, stolen sessions, or unsafe downloads. Understanding those boundaries helps organizations choose the right combination of defenses.
Passkeys offer a different kind of evidence at sign-in: cryptographic proof tied to the service being accessed. FIDO2 security keys can provide a physical place to hold and use those credentials. Their value becomes clearer when we separate three questions: Who is signing in? Which service are they signing in to? What action are they authorizing?
How does AI change phishing attacks?
Microsoft’s April 2026 research described a device-code phishing campaign combining automation with personalized lures generated using AI. The examples included messages tailored to business activities such as invoices and requests for proposals. The significance is not that every suspicious message now comes from AI. It is that attackers can combine plausible content with automated infrastructure. Microsoft’s campaign research
There is also a distinction between AI-assisted attacks and AI-themed attacks. In September, Microsoft described campaigns borrowing the names of popular AI services to promote phishing pages or malicious downloads. Impersonating a service is not evidence that the service itself has been breached. Research on AI-themed attacks
Our interpretation is that awareness training remains useful, but it should be supported by controls that continue working when a message looks persuasive.
How do passkeys resist fake login pages?
NIST defines phishing resistance around preventing an impostor verifier from obtaining usable authentication secrets or outputs without depending on the user’s vigilance. It identifies WebAuthn, used in FIDO2, as a standard that binds authentication to a verified service name. Manually entered one-time codes do not provide that same binding. NIST authentication guidance
In a properly implemented WebAuthn sign-in, a lookalike website cannot simply request the legitimate website’s credential as though it belonged to the impostor’s domain. This changes a critical step in conventional credential phishing. A copied login page may look convincing, but appearance alone does not give it the cryptographic identity of the real service.
That protection addresses a particular failure mode. It should not be stretched into a claim that all social engineering becomes harmless.
When should you use a FIDO2 hardware security key?
The FIDO Alliance describes both synced and device-bound passkeys. A FIDO2 security key can hold a device-bound credential; a synced passkey can make credentials available across devices through a passkey provider. Both approaches can support phishing-resistant sign-in. The choice affects custody, convenience, and recovery, rather than making one category universally appropriate. FIDO Alliance overview
For a business, a separate hardware authenticator may fit employees who move between supported computers or cannot use a personal phone. For an individual, it may offer a deliberate, tangible way to manage access to important accounts.
Our recommendation is to choose based on the account and workflow. Start with email, administrative access, and other accounts whose compromise would expose additional systems. Check each service’s support for external security keys, then test registration, regular use, and recovery.
Which attacks still need protection beyond passkeys?
Device-code phishing illustrates the boundary. An attacker can persuade a victim to enter an attacker-supplied code at a legitimate sign-in service, authorizing a session the attacker initiated. The problem is then the purpose of a real authentication flow, rather than only the identity of a fake website. A passkey alone does not establish that the user intended to authorize that remote session. Microsoft’s research describes token issuance without password theft and recommends controls on the device-code flow. Attack mechanics and mitigations
Likewise, a passkey does not inspect a downloaded installer or decide whether a payment request is legitimate. Microsoft’s AI-themed campaign analysis includes malware delivery and theft of payment information, which require defenses beyond the login credential. Campaign analysis
How to evaluate your phishing-resistant authentication rollout
A useful evaluation asks more than whether a product is “AI-ready.” Our recommended measures include the proportion of important accounts using phishing-resistant authentication, the number of weaker fallback paths still enabled, and how quickly a lost authenticator can be revoked and replaced.
Test a fake-domain sign-in scenario separately from recovery and authorization scenarios. Keep endpoint protection and session monitoring in the plan. Give employees a simple rule for unexpected device codes: do not enter a code for a device or sign-in they did not initiate.
Explore Thetis FIDO2 security keys when a physical authenticator fits your environment. The objective is a verifiable sign-in process with a usable recovery path. In an age of increasingly convincing imitation, that is a concrete improvement organizations can make today.
Research-based explainer; sources checked September 29, 2026. Recommendations are editorial analysis, not results of a new experiment.
