Reported phishing toolkit may preserve access through attacker-controlled passkeys
THE BRIEF
SecurityWeek reports that researchers said an iAuthFlow V2 phishing toolkit can register an attacker-controlled passkey and retain access after password resets and session revocation. The capability remains unverified in the supplied record.
WHY IT MATTERS
Password resets may not remove every identity credential. Unauthorized passkeys or other newly registered authenticators can provide persistence if registration and recovery controls are weak.
WHO SHOULD CARE
Identity teams, help desks, application owners, fraud operations and incident responders.
WHAT TO DO NOW
- Alert on new passkey or security-key registration, especially immediately after a suspicious login, recovery event or password reset.
- Include registered authenticators, passkeys, OAuth grants and recovery methods in account-compromise investigations.
- Require strong reauthentication and appropriate approval for authenticator changes on privileged and high-value accounts.
- Provide a documented process to revoke unknown passkeys and verify the user through an independent channel.
VERIFICATION NOTE
Primary research source is supplied, but the reported toolkit capabilities remain unverified in the candidate record.