Attackers don’t break passkeys directly — they convince the browser not to use them, quietly falling back to passwords.
- The attack targets the fallback path rather than the passkey cryptography itself.
- When a stronger method is skipped, weaker password authentication takes over.
- Defenders should watch where strong authentication can silently downgrade.
This briefing is part of SecureW2’s Cybersecurity Intelligence series, which tracks identity, certificate, and network-security events for the teams who have to respond to them.