Report Fraud’s call to switch to passkeys is backed up by the numbers. Account takeover losses rising from £1.2m to £6.3m in a year show how much criminals extract once they are inside an email or social media account.
Passkeys are a meaningful upgrade. A passkey is a cryptographic key stored on a personal device and tied to a genuine website. A fake login page cannot collect it, because there is nothing to type and nothing to hand over. It also removes the temptation to reuse passwords, which remains the most commonly observed insecure behaviour among employees, according to 35% of UK security leaders surveyed by Keeper Security.
The practical challenge is managing them securely across your devices. A password manager stores your passkeys in an encrypted vault and makes them available wherever you need them, while also protecting your recovery codes and backup credentials. It handles passwords for the services that do not yet support passkeys. As more websites adopt passkeys, you can transition gradually. Start by securing your main email account with a passkey and strong recovery options, then move social media and banking to passkeys. For accounts holding health or financial records, consider going a step further with a hardware security key. The credential lives on a physical device that is never synced to the cloud, which reduces dependence on your platform account and recovery process.






