Your account may be attacked up to 700 times a second: Microsoft’s move to passkeys

Microsoft reports 7,000 password attacks per second Global move to passkeys

Microsoft recently announced a major shift in its approach to account security: a move away from passwords and toward passkeys. This decision comes as the company reports blocking an unprecedented 7,000 password-related attacks every second. The numbers reveal a clear conclusion—passwords are no longer a reliable defense against cyberattacks.

In this article, we’ll explain Microsoft’s decision, introduce passkeys and why they’re a better solution, show how users and businesses can adopt them, and provide an update on how passkeys are being used today.


Why is Microsoft replacing passwords with passkeys?

Microsoft’s decision is a response to the dramatic rise in password-based attacks. The company’s data shows that phishing attempts, brute-force attacks, and other forms of credential theft have reached alarming levels. Cybercriminals exploit human error, weak passwords, and outdated security methods to steal account access, leading to data breaches and financial losses.

By adopting passkeys, Microsoft aims to reduce these risks while making account access simpler for users. Passkeys provide stronger protection against common threats and eliminate the vulnerabilities associated with passwords, such as reuse and poor complexity.

How to Implement Passwordless Logins with Passkeys A Secfense Guide

What are passkeys, and why are they a better solution?

Passkeys are a secure alternative to passwords, based on public-key cryptography. They work by creating a pair of keys:

  • A private key, stored securely on your device, and
  • A public key, shared with the service you want to access.

When you log in, the private key remains on your device and is used to verify your identity, while the public key interacts with the service. This process makes passkeys immune to phishing, as they cannot be stolen or tricked out of a user like passwords can.

Why passkeys are better:

  • Stronger security: Passkeys cannot be guessed, reused, or exposed in data breaches.
  • Simpler logins: With passkeys, users can authenticate with built-in options like a fingerprint, face scan, or PIN.
  • Protection of the private key: The private key never leaves the device, ensuring it cannot be extracted or stolen, even if the targeted application is compromised – contrary to leaked passwords or TOTP seeds.
  • Phishing resistance: Native, built-in mechanisms in most operating systems and browsers are in place to prevent attackers from tricking users into revealing sensitive credentials, such as on fake websites or via fraudulent emails.
  • Cross-device usability: Passkeys are designed to work across devices and platforms, offering seamless access to accounts.

Microsoft’s move to passkeys aligns with global security standards such as FIDO2, which are designed to reduce dependency on passwords and protect against evolving cyber threats.

Achieving Passwordless Logins A Secfense Report on Using Passkeys

Where are passkeys already being used?

Passkeys are not new. They’ve already been adopted by major companies and platforms:

  • Apple: Introduced passkeys via iCloud Keychain, enabling users to log in securely across iOS and macOS devices.
  • Google: Integrated passkeys into Google Password Manager, making them available on Android and Chrome.
  • PayPal: Allows customers to authenticate with passkeys on supported devices.
  • Dropbox: Offers passkey support for secure access to its services.

How you can start using passkeys:

  • On iPhones and Macs: Enable passkeys through iCloud Keychain in your device settings.
  • On Android: Use Google Password Manager to manage and activate passkeys.
  • On Windows: Leverage Windows Hello to authenticate with biometrics.

More apps and websites are adding passkey support every day. To check if a service supports passkeys, look for FIDO2 or passkey options in its account settings.


Passkey adoption in businesses: What’s next?

The shift to passkeys is gaining momentum in the business world, as organizations see the benefits of reducing password-related risks. However, adoption is still in its early stages for many companies.

Current landscape:

  • Large tech companies like Microsoft, Google, and Apple are leading adoption efforts.
  • Small and medium-sized businesses are starting to explore passkeys, often driven by the need to comply with security regulations like GDPR, DORA, and NIS2.

Challenges for businesses:

  • Technical integration: Legacy systems may require updates to support passkeys.
  • User education: Employees and customers need clear instructions to transition smoothly.
  • Regulatory compliance: Businesses must ensure that passkey adoption meets industry and legal standards.
Passkeys Are Now More Portable and Easier to Implement with CXP and Passkey Central

Opportunities:

  • Reduced password-related support requests, saving time and IT resources.
  • Improved user satisfaction due to faster, simpler authentication methods.
  • Enhanced security, minimizing the risk of breaches caused by weak or stolen passwords.

Solutions like Secfense can simplify the process for businesses by enabling passkey adoption without replacing existing systems. With tools that integrate passwordless authentication into current applications, organizations can transition to passkeys quickly and securely.

Explore how passkeys improve security and cut costs - Schedule a call with Secfense to learn more

Make the move to passkeys

Talk to a Secfense expert: Ready to enhance your security with passkeys? Contact us today for guidance on adopting passwordless authentication in your business.

Learn more in our webinar: Find out how passkeys work and why they’re the future of authentication. Watch our webinar for insights and actionable steps to start your passwordless journey.

Antoni takes care of all the marketing content that comes from Secfense. Read More

Testimonials

We are faced with new challenges every day. We must always be one step ahead of the attackers and know what they are going to do before they do it. We are convinced that the User Access Security Broker will bring security to a new level, both for those working at the office and from home. For us, working with Secfense is an opportunity to exchange experience with developers who put great value on out-of-the-box thinking.

Krzysztof Słotwiński

Business Continuity and Computer Security Officer

BNP Paribas Bank Poland

As part of the pre-implementation analysis, we verified that users utilize a wide range of client platforms: desktop computers, laptops, tablets, smartphones, and traditional mobile phones. Each of these devices differs in technological advancement, features, and level of security. Because of this, and also due to the recommendation of the Polish Financial Supervision Authority (UKNF), we decided to introduce additional protection in the form of multi-factor authentication mechanisms based on FIDO. As a result, users of our applications can log in safely, avoiding common cyber threats such as phishing, account takeover, and theft of their own and their clients’ data.

Marcin Bobruk

CEO

Sandis

We are excited to partner with Secfense to enhance our user access security for our web apps. By integrating their User Access Security Broker, we ensure seamless and secure protection for our applications and systems, delivering superior security and convenience to our customers.

Charm Abeywardana

IT & Infrastructure

Visium Networks

Before investing in Secfense, we had the opportunity to talk to its existing clients. Their reactions were unanimous: wow, it’s so easy to use. We were particularly impressed by the fact that implementing their solution does not require the involvement of IT developers. It gives Secfense a huge advantage over the competition, and at the same time opens the door to potential customers who so far were afraid of changes related to the implementation of multi-factor authentication solutions.

Mateusz Bodio

Managing Director

RKKVC

Even when the network and infrastructure are secured enough, social engineering and passwords can be used to gain control of the system by attackers. Multifactor authentication is the current trend. Secfense addresses this and allows you to build zero trust security and upgrade your current systems to passwordless applications within minutes, solving this problem right away,” said Eduard Kučera, Partner at Presto Ventures and cybersecurity expert – former Director in hugely successful Czech multinational cyber security firm Avast.

Eduard Kučera

Partner

Presto Ventures

One of the biggest challenges the world is facing today is securing our identity online. That’s why we were so keen to have Secfense in our portfolio. They make it possible to introduce strong authentication in an automated way. Until now, organizations had to selectively protect applications because the deployment of new technology was very hard, or even impossible. With Secfense, the implementation of multi-factor authentication is no longer a problem, and all organizations can use the highest standards of authentication security.

Stanislav Ivanov

Founding Partner

Tera Ventures

Two-factor authentication is known to be one of the best ways to protect against phishing; however, its implementation has always been difficult. Secfense helped us solve that problem. With their security broker, we were able to introduce various 2FA methods on our web applications at once.

Dariusz Pitala

Head of IT

MPEC S.A.