Blog/Phishing

Passkeys: The Sign-In Method Phishing Can't Steal

Passkeys are tied to the real website, so a fake login page has nothing to steal. How passkeys defeat phishing, where they still fall short, and how to start using them.

CyberWatch AI2 October 2026 · 2 min read
A single key on a black background

Most phishing is about getting you to type something into the wrong place: a password, a code, a card number. Passkeys remove the thing you type. That is why they are one of the most effective defences against phishing available to ordinary people today.

Why a fake login page cannot catch a passkey

When you create a passkey, your device makes a pair of keys. The website keeps the public half. The private half stays on your phone, computer or password manager and is only unlocked by your fingerprint, face or screen lock.

Crucially, the passkey is tied to the real website's address. If you land on hxxps://account-verify-login[.]com, your device simply has no passkey for that address and offers nothing. There is no secret for the fake page to collect and nothing you can be tricked into typing.

What passkeys do not fix

  • Scams that persuade you to pay, transfer or approve something yourself.
  • Weak fallbacks: if the account still accepts a password or a text code, a phisher can target that instead. See why text codes are weaker.
  • Recovery tricks, where someone talks you into sharing a recovery code or approving a new device.

How to start

  1. Begin with your email account, since it can reset everything else.
  2. Add passkeys to banking, shopping and social accounts that offer them.
  3. Keep a second passkey or recovery method so a lost phone does not lock you out.

Our step-by-step guide covers setting up passkeys, and what a passkey is explains the basics.

Still getting login warnings by email? Paste them into CyberWatch AI Scan to check before you act.

For the full picture, see how to protect yourself from phishing.

Frequently asked questions

Can a phishing site steal my passkey?

No. A passkey only works on the website it was created for, and the private part never leaves your device, so a lookalike site cannot use or capture it.

Do passkeys stop every kind of phishing?

They stop password and code theft on fake pages. They do not stop scams that talk you into sending money, approving a payment or reading out a recovery code.

Should I delete my password after adding a passkey?

Where a service lets you, removing or strengthening the password and other weak fallbacks makes the account harder to phish.

Sources

  1. Sign in with a passkey instead of a password, Google Account Help
  2. Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
  3. Multi-factor authentication for your corporate online services, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.