COLUMNS

Passkeys crack the code on safer logins

Written by Dr. Mehak Jonjua/Journalist, Author & Media Mentor | Oct 4, 2026, 7:07:42 PM

For decades, passwords have served as the traditional key to digital life, yet they have also been one of the biggest security weak spots. Cybercriminals use phishing, credential theft, and password reuse to attack both users and organizations.

Passkeys offer a different solution: instead of a simple password that can be easily compromised, they use cryptographic credentials stored on the user’s device and accessible only through a fingerprint, face scan, or PIN code.

Data from breaches at different firms supports the new password alternative. Verizon's 2025 Breach Investigation Report indicates that credential-related crimes account for 22% of all breaches, and phishing crimes account for 16%.

In total, 88% of all web-based attacks involve stealing credentials. Password reuse also enlarges the attack surface. On average, no more than 49% of a person's passwords across different services are unique, which turns credential stuffing into a distribution channel. In 2024 alone, the number of leaked and sold passwords totaled 2.8 billion.


Passkeys rely on public-key cryptography—the same mechanism that enables secure web traffic. A passkey owner has a private key stored on the device, accessible only with a fingerprint or face biometric. The matching public key is stored on the site itself. This makes impersonated webpages useless to hackers.


Passkeys have already been adopted widely. According to the FIDO Alliance, 5 billion passkeys have been implemented worldwide, 90% have heard the term, and 75% have at least one passkey enabled. 68% of companies have already used, or plan to use, the technology for enterprise authentication.


Passkeys are already helping organizations. Google has reported about 800 million accounts secured with the technology and successful sign-ins among 30% of users, making login 20% faster. Amazon users generated 175 million passkeys in the first year, cutting login time by six times. Microsoft reported a 98% passkey success rate, while passwords achieved a 98% success rate. The practice was effective at Japan's Mercari, which achieved an 82.5% success rate; VicRoads in Australia reached all logins with passkeys within seven years, while HealthiWealth saw a reduction in mobile account takeover fraud.


Nonetheless, the transition process is not complete, as most companies still use passwords, and 57% rely on phishing for primary sign-ins. Account recovery after losing the device still needs attention.