A reported phishing-kit technique can steer a victim away from FIDO authentication and toward a weaker sign-in method—but it does not crack FIDO or steal its private key. In an August 2025 proof of concept targeting Microsoft Entra ID, the attacker relayed a sign-in, prompted the victim to use an alternative authentication method, then captured the resulting credentials and session cookie. Proofpoint said it had not observed this specific technique in the wild when it published its report.
What the reported FIDO downgrade attack does
The attack exploits a gap between a service supporting FIDO and a service requiring FIDO. If the account can still authenticate with a phishable fallback—such as a password plus another weaker factor—an attacker may trick the user into choosing that route instead. The weakness is in the available authentication path and the user’s ability to be steered onto it, not in FIDO’s cryptography.
Proofpoint’s August 12, 2025 report describes a proof of concept against Microsoft Entra ID using a custom phishlet for the Evilginx adversary-in-the-middle (AiTM) framework. The report does not establish how many tenants or victims were affected, or a prevalence rate for this method. Proofpoint’s technical report
How the attack works
- The victim opens a phishing link. The link leads to a relayed sign-in page controlled by the attacker.
- The relay presents an unsupported browser identity. The phishlet supplies Microsoft with a spoofed browser and operating-system user-agent combination that does not support FIDO in the relevant Entra ID flow.
- The sign-in flow offers another method. Microsoft returns an error and presents an alternative authentication option. The phish page encourages the victim to select it.
- The victim completes the weaker route. If the account has an alternative method enabled and the user enters credentials and completes that challenge, the relay can capture the credentials and session cookie.
- The attacker reuses the session. Importing the captured cookie may let the attacker access the authenticated session without repeating the MFA challenge.
The flow depends on a weaker alternative authentication method remaining available for the account. A FIDO2 security key or passkey can provide strong, origin-bound authentication, but owning one does not force a service to reject its other sign-in methods. Dark Reading’s independent summary
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Does this break FIDO security keys or passkeys?
No. FIDO/WebAuthn binds public-key authentication to the relying party’s origin, which makes ordinary credential-relay phishing ineffective against the FIDO assertion itself. The reported attack does not demonstrate extracting a FIDO private key, forging a FIDO assertion, or defeating that origin binding. Instead, it attempts to move the user to a different method the service still accepts.
That distinction matters: “FIDO is bypassed” can sound like the cryptographic protection failed. In this case, the demonstrated risk is that the authentication policy permits fallback and a convincing relay can persuade a user to take it. The same broader concern applies to enrollment and recovery: if an attacker can access an account through a phishable login or weak recovery process, they may be able to register a passkey or route around passkey sign-in. FIDO Alliance guidance on partial phishing prevention
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What is known about real-world use
Proofpoint described its Entra ID technique as a proof of concept and reported no evidence of in-the-wild use as of August 12, 2025. It also said adapting the phishlet required more technical skill than simpler attacks commonly used. The possibility that a technique could be integrated into commercial phishing kits is not evidence that a particular kit or campaign has deployed it.
The underlying idea predates this proof of concept. A 2021 USENIX Security study examined social-engineering downgrade attacks against FIDO U2F. In the study’s designed scenario and participant sample, 55% of participants fell for real-time phishing, while another 35% were potentially susceptible in practice. Those figures describe that study, not the general population and not Proofpoint’s 2025 Entra ID flow. The researchers also found that all FIDO-supporting sites in their historical Alexa top-100 sample allowed users to choose alternatives to FIDO; this is not a finding about all websites today. USENIX Security 2021 paper page
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How organizations can reduce downgrade risk
Restrict phishable fallback where practical
Require phishing-resistant authentication for high-risk accounts and sensitive operations where the organization can support it. Remove weaker alternatives for selected users or functions when feasible. The FIDO Alliance describes staged, partial enforcement as an option when immediate passkey-only access would disrupt legitimate users. A fallback policy should be an intentional exception, not an unnoticed route around the stronger method.
Secure passkey enrollment and account recovery
Require strong verification before registering a new passkey or recovering an account. Email or SMS one-time codes alone can become a weaker side door if they are easier to phish or take over than the passkey they are meant to back up. The FIDO Alliance identifies protecting enrollment and recovery as part of a phishing-prevention strategy. FIDO Alliance deployment guidance
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Keep usable recovery options without making them easy to abuse
People lose devices, encounter unsupported hardware, or need to sign in when a primary authenticator is unavailable. Removing every fallback without a tested recovery plan can lock out legitimate users. Organizations adopting passkey-only access should decide in advance how to restore access securely, who can authorize recovery, and how exceptions will be reviewed.
Review authentication and session activity
As a defensive operational measure, review unexpected fallback use, newly registered authenticators, and anomalous session activity. These checks follow from the attack’s steps; the cited reports do not prescribe a specific Entra ID detection rule.
Recommended Free Tools
Best Value
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Protect the surrounding devices and accounts
Passkeys do not remove the need to secure endpoints, browsers, or any account used to synchronize passkeys. The UK National Cyber Security Centre highlights the security of the synchronization fabric and the continuing importance of device and browser security. NCSC guidance on traditional and FIDO2 credentials
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why services retain fallback—and the trade-off
Fallback helps people authenticate when a device or browser cannot use the preferred method, but each additional route can weaken a phishing-resistant policy. In an August 2025 Dark Reading interview, Bojan Simic, a FIDO Alliance board member and HYPR CEO and co-founder, described the operational tension: “Fundamentally, for companies like Microsoft and others who are key players in this ecosystem, the number one priority is to make sure that users are able to authenticate. That doesn’t necessarily mean their number one priority is to protect the authentication at all costs,” Dark Reading, August 14, 2025
Simic also said, “But that is still very rare to see, unfortunately,” in the specific context of some large crypto exchanges allowing users to turn off MFA after enrolling a FIDO passkey, thereby removing SMS fallback. That observation should not be read as a statement about all services or all MFA policies. Dark Reading interview
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

