Passkeys make sign-ins faster and more secure by using device-based cryptography instead of passwords. But attackers are adapting: they look for ways to sneak a new passkey onto your account so they can log in without your knowledge. The good news is you can usually spot and block these attempts before they succeed by reading security emails closely and checking device and account logs. This guide shows you what to look for, how to verify legitimate activity, and the exact steps to take if something looks wrong.
What a Passkey Is—and Why Attackers Want to Add One
A passkey is a cryptographic credential stored on your phone, laptop, security key, or cloud-synced password manager that proves to a website or app that it’s you. It replaces or complements passwords and one-time codes. Because passkeys are phishing-resistant and convenient, criminals increasingly aim to register their own passkey on your account—often by tricking you into confirming a login or by exploiting a session you already opened. If successful, they can bypass passwords and many forms of two-factor authentication.
Common Signals of Unauthorized Passkey Registration
Most services provide notices and logs that reveal when a new passkey or security key is added. Treat any unexpected notice as urgent. Key signals include:
- Security emails about a “new passkey” or “new security key.” Messages often include device type, browser, approximate location, and time.
- Account activity logs showing a new authenticator. Many platforms provide an audit trail under Security or Login & Devices.
- Device lists that suddenly include unfamiliar hardware or browsers. Look for new entries you didn’t add (e.g., a Windows PC when you only use Mac).
- Push prompts at odd times. “Are you trying to sign in?” prompts can be attacker-triggered attempts to social-engineer your approval.
- Recovery settings quietly changed. New recovery email, phone, or backup passkey enrollment can indicate a takeover in progress.
Read Security Emails Like a Forensics Report
Security emails are often your earliest warning. Scan them with a checklist approach:
- Subject line: Look for phrases like “New passkey added,” “Security key registered,” “New device sign-in,” or “2-step verification changed.”
- Timestamp: Compare to your recent activity. If you weren’t signing in at that time, assume misuse.
- Device and platform: Do you own that device type and OS? Mismatched platform is a red flag.
- Browser or app: Did you use that browser version or app build?
- Location/IP (approximate): Geo in a different city or country suggests compromise. Beware of VPNs: if you use one, verify whether the location matches your VPN exit.
- Action links: Many emails include “Secure your account,” “Undo,” or “Review devices.” Use these from a trusted bookmark instead of clicking the email link—just in case the email is spoofed.
Verify Using Your Device and Account Logs
After seeing any unexpected email, check your logs directly from the service—never from the email link. Use a known-good bookmark or type the site URL manually.
- Account security dashboard: Look for sections like “Passkeys,” “Security keys,” “Two-factor authentication,” “Devices,” or “Recent activity.” Confirm whether a new passkey or device was added and the exact time.
- Device lists: Remove any device you don’t recognize. If unsure, sign out of all sessions and re-authenticate only on trusted devices.
- Browser/device logs: Your operating system and browsers keep sign-in and device association traces. If you use a password manager with passkeys, review its “connected devices” or “authorized clients.”
- Email account activity: Check your email provider’s recent activity log. If attackers control your email, they can complete passkey enrollment flows and hide alerts.
Spot the Tactics Attackers Use
Understanding common techniques helps you act faster:
- Push fatigue social engineering: Attackers trigger repeated approval prompts, hoping you’ll tap “Yes” to silence them, which can register a new key or confirm a login.
- Session riding: If you’re already logged in on a compromised device or malicious tab, attackers might start a passkey enrollment that appears legitimate.
- Phishing overlays: Fake pages that mimic genuine “Add passkey” flows to capture your credentials and pivot to the real account.
- SIM swap and email takeover: Control over your phone number or inbox lets attackers intercept enrollment confirmations.
How to Confirm Whether a Passkey Addition Is Legitimate
Use a quick decision tree:
- Did you personally start a passkey setup on that service within the last few minutes? If no, treat as suspicious.
- Does the device, OS, browser, and location match exactly what you used? Minor version differences are normal, but major mismatches are not.
- Can you see the new passkey in your account’s Security > Passkeys list? If present and you didn’t add it, remove it immediately.
- Is there any concurrent sign-in from an unknown device? If yes, sign out all sessions and change your password from a clean device.
Immediate Steps if You See a Suspicious Passkey Registration
Act within minutes to reduce the chance of a full takeover:
- Open the account’s security dashboard using a trusted bookmark or directly typed URL.
- Remove the unfamiliar passkey or security key from the Passkeys/Security Keys list.
- Sign out of all sessions/devices and require re-authentication.
- Change your password to a new, unique one generated by a password manager.
- Re-lock your account with strong MFA (authenticator app or hardware key). Avoid SMS if possible.
- Review recovery options and replace any recovery emails, phone numbers, or backup codes that could be abused.
- Check email account security (password, recovery info, recent activity) since it’s the hub for security alerts.
- Scan devices for malware and update OS, browser, and extensions. Remove unneeded extensions.
Where to Look: Popular Services and Their Security Sections
While names change over time, most providers organize controls similarly:
- Email and identity hubs: Account Security > Passkeys, Security Keys, Two-Step Verification, Devices, Recent Activity.
- Banks and brokerages: Profile > Security > Login and devices, Manage authenticators, Sign-in approvals.
- Retailers and delivery: Account > Login & Security > Two-step verification, Trusted devices.
- Social media and communications: Settings > Security > Passkeys/Keys, Sessions, Apps and browsers, Where you’re logged in.
If you cannot find the passkey list, search the site’s help center for “passkeys,” “security keys,” or “FIDO2/WebAuthn.”
Preventive Settings to Block Future Unauthorized Enrollments
Build layers so a single mistake doesn’t lead to a full compromise:
- Require re-authentication for security changes: Some services let you demand a password or key confirmation before adding a passkey or changing MFA.
- Use hardware security keys for admin actions: If supported, require a physical key for enrolling new passkeys or changing recovery settings.
- Turn on sign-in alerts everywhere: Email and push alerts for new devices, passkeys, and password changes catch issues early.
- Reduce attack surface: Remove old devices, unused authenticator apps, and stale recovery methods. Fewer entry points mean fewer surprises.
- Lock down your email: Enable strong MFA, disable less-secure app access, and review forwarding and filters that could hide security messages.
- Use a reputable password manager: Generate unique passwords and store passkeys on devices you control; disable cloud sync for passkeys if you don’t need it.
Differentiate Real Security Emails from Phishing
Attackers imitate “new passkey” alerts to make you click. Reduce risk by:
- Ignoring embedded links: Access your account from a bookmark or by typing the URL, then verify alerts in the security dashboard.
- Checking sender domain and DKIM/DMARC indicators in your email client. Mismatched domains or missing authentication are red flags.
- Looking for generic greetings and urgent scare language: Real notices usually include precise details (device, time) and don’t demand instant clicks.
- Comparing with your known alert style: Save a legitimate alert as a reference to spot format or wording differences later.
What If an Attacker Already Added a Passkey?
If the attacker succeeded, you may still have time:
- From a clean device, reset your password and immediately remove all unfamiliar passkeys.
- Sign out all sessions and re-enable MFA using an authenticator app or hardware key.
- Rotate recovery options (backup codes, recovery email/phone) to prevent re-entry.
- Review connected apps and API tokens and revoke anything you don’t recognize.
- Check financial and high-value accounts for changes, transfers, or new payees. If you find fraud, contact the provider’s fraud team right away and file appropriate reports.
Build a Personal Monitoring Routine
A simple weekly and event-driven routine can catch most issues early:
- Weekly: Review your primary email’s security alerts, check “Devices” and “Passkeys” on your most important accounts, and remove anything you don’t recognize.
- After any suspicious email or prompt: Verify logs immediately, sign out all sessions if unsure, and rotate your password/MFA.
- After traveling or using shared networks: Recheck device lists and recent activity, and update software.
When Credit and Identity Monitoring Helps
Attempts to add a passkey often accompany broader identity risk—like account openings, password resets, or changes to recovery contact points. In addition to tightening your login security, consider continuous monitoring for identity-related changes that could indicate fraud across accounts. A specialized service can alert you to new credit inquiries, account changes, and other signals that deserve a closer look. If you want a single place to monitor credit and identity-related activity while you lock down your accounts, see SmartCredit’s privacy, credit monitoring, and identity-protection resource.
Quick Reference: Your 10-Minute Response Plan
- Open the site from a trusted bookmark and go to Security.
- Remove any unfamiliar passkey/security key.
- Sign out of all devices/sessions.
- Change your password to a unique, manager-generated one.
- Re-enable MFA with an authenticator app or hardware key.
- Review recovery options and replace anything suspicious.
- Check your email account security and recent activity.
- Scan for malware and update OS/browsers/extensions.
- Review high-value accounts for changes or alerts.
- Set stronger alerts and re-authentication requirements for future changes.
Conclusion
Unauthorized passkey registration is a fast-moving attack, but it leaves early clues in security emails, device lists, and account logs. By reading alerts carefully, verifying details directly in your security dashboard, and acting within minutes to remove unknown credentials, you can stop intruders before they gain lasting access. Build a simple checkup routine, strengthen recovery settings, and keep strong MFA in place so a single mistake doesn’t become a takeover. Stay alert, verify before you click, and make your accounts prove new devices and passkeys really belong to you.
Good to Know
Most services send a time-stamped notice when a passkey or security key is added. If the time, device, or location doesn’t match your actions, revoke the new credential immediately and rotate your sign-in methods.