Passkeys secured the login. Not the lifecycle.
A passkey cannot be phished, so attackers went after enrollment, sync, and recovery instead, now with real-time voice cloning. Here is how to defend recovery against a call that sounds like anyone.
A passkey cannot be phished. So this summer, attackers stopped trying, and went after everything around it.
Since April, a crew Okta tracks as O-UNC-066 has been phoning Microsoft 365 users, posing as IT, walking them through a fake passkey-enrollment page. They phish the password and the MFA code, sign in as the victim, and register a passkey of their own on Microsoft's real portal. It is genuine, phishing-resistant, and it belongs to the attacker. Tech, healthcare, aviation, and more.
The only thing that ever throttled this was needing a convincing human on the line, one call at a time. That ended last week. SpaceXAI and OpenAI both shipped real-time voice that clones anyone from a two-minute clip. Pull the CEO's earnings call off YouTube and "an urgent call from IT" becomes an urgent call from the CEO, in his own voice, dialing every extension at once.
Passkeys only ever secured one moment: the login. They say nothing about the three around it, enrolling a credential, syncing it, recovering it. Recovery is the softest, because recovery is where every product keeps a shortcut: an email reset, an SMS code, a security question, a support desk that folds under pressure. A phone call that now scales finds that shortcut every time.
So how do you actually defend recovery against a call that is cheap, endless, and sounds like anyone?
Kill the shortcut first. No email reset, no SMS code, no security question, no override an operator can be talked into. If there is an automated way back in, a scaled phone bank will find it. Recovery has to demand something a caller simply cannot phish.
Then stop holding the keys you would use to let someone back in. If the provider can reconstruct a user's vault, so can whoever breaches the provider, and so can a subpoena. Split the recovery secret in two: give the user one half, keep a half that is useless alone, and rebuild the key on the user's own device. Now a database breach is a pile of noise, and there is nothing to hand a court.
Last, and this is the part the voice models break, the human check cannot be a question. "What is your mother's maiden name" tells the attacker exactly what to go find, and it was in a breach years ago. So ask nothing. Let the user decide in advance how they will prove themselves, and keep it secret from everyone, so the operator says only "prove it" and the caller has to already know the answer: a phrase only they would pick, or an object chosen live from a source they named that you never say out loud. A cloned voice can fake any answer it is handed. It cannot produce the right answer to a question that was never asked.
None of that is free. No override means a user who loses both their devices and their secret is locked out for good, the correct trade for a vault no one else can open. And the proof is only as private as the user keeps it. But recovery built this way survives the exact attack now being automated against everyone else, because there is no shortcut to phish, no key to steal, and no question to answer.
That is what recovery has to be now. And that is exactly what we did.
Clavitor (@clavitorai) is the credential vault built for AI agents, and against them. clavitor.ai
Sources
Okta Threat Intelligence (@okta): "Vishing actors target Microsoft Entra passkey enrollment." The O-UNC-066 campaign: attackers phish a password and MFA code by phone, sign in as the victim, then register their own FIDO2 passkey through Microsoft's legitimate Entra Security-info portal. [1]
BleepingComputer (@BleepinComputer): "Entra passkey enrollment vishing targets Microsoft 365 users." [2]
SpaceXAI (@SpaceXAI): the Voice Agent Builder and Custom Voices launch, a no-code real-time AI voice-agent platform that clones a voice from a roughly two-minute clip. OpenAI's comparable model is GPT Realtime 1.5. [3]
(Verify handles are live before posting: @okta, @BleepinComputer, @SpaceXAI.)