Passkey Authentication: Is It Finally Time to Ditch Your Passwords?
Updated August 1, 2026
In June 2026, attackers broke into Chick-fil-A One loyalty accounts and got away with names, addresses, birthdates, gift card balances, and partial payment card numbers. That part isn’t unusual. What is unusual: this was the second time the exact same attack worked against the exact same company. A near-identical breach in 2022-2023 had already compromised over 71,000 accounts the same way: credential stuffing, where attackers take usernames and passwords stolen from some other, unrelated breach and simply try them against a different login page. It works because people reuse passwords, and it keeps working until there’s nothing left to steal and reuse.
Chick-fil-A offers multi-factor authentication on these accounts. It just doesn’t require it – and credential stuffing only needs a password to succeed, so an optional second step that most people skip doesn’t stop it. That’s the real story here, and it’s the whole case for passkeys: as long as a reusable secret exists, someone will eventually reuse it somewhere it gets stolen. Passkeys don’t add a second step to the password. They remove the password.
Why This Keeps Happening
Verizon’s research into credential attacks found that among users infected with password-stealing malware, only 49% had used a distinct password for every service – meaning one leaked password routinely opens more than one door. Credential stuffing attempts built on exactly that pattern made up a median 19% of all daily authentication attempts across the organizations Verizon studied. Credential compromise of some kind showed up in 39% of breaches in this year’s Data Breach Investigations Report.
Chick-fil-A’s repeat breach is what that looks like in practice: the company had a mitigation available (MFA) and it still didn’t hold, because the mitigation was optional and the underlying vulnerability – a password that works anywhere a person has reused it – was never actually removed.
What Is Passkey Authentication?
A passkey is a digital credential that replaces your password entirely, rather than adding a step on top of it. Instead of typing something you memorized, your device (phone, laptop, security key) proves who you are using cryptography, then unlocks that proof with your fingerprint, face, or device PIN. There’s no shared secret transmitted or typed anywhere – which means there’s nothing for a credential-stuffing attack to steal and reuse in the first place.
Under the hood, this runs on WebAuthn, part of the FIDO2 standard, using public-key cryptography: your device holds a private key that never leaves it, and the website holds a matching public key that’s useless to an attacker on its own. That’s the plain-language version – what matters for a business is simpler: a passkey can’t be phished, guessed, reused, or bought off a leaked-password list, because there’s no password to phish, guess, reuse, or buy.
Why This Isn’t the Same as Just Adding MFA
Multi-factor authentication is still genuinely effective, and we recommend it everywhere passkeys aren’t yet an option (more on that below). But Chick-fil-A’s repeat breach shows its limit: MFA is a second lock on a door that still has a copyable key. If it’s optional, people skip it. If it’s SMS-based, it can be intercepted. Passkeys remove the copyable key instead of adding a second lock – there’s no password for an attacker to have stolen from some other breach in the first place, so credential stuffing has nothing to work with.
What Passkeys Actually Get You
More Secure
Because there’s no shared secret to leak, reuse, or phish, passkeys close off the entire category of attack behind the Chick-fil-A breach and the 39% of breaches involving credential compromise cited above. Organizations that have deployed passkeys report a 32% reduction in phishing-related incidents, plus fewer helpdesk tickets and faster logins along the way.
More Convenient
There’s no password to remember, forget, or reset, and no complexity rules to satisfy. Logging in is usually a fingerprint or face scan – faster for employees and customers alike, and one less recurring helpdesk request for your IT provider to field.
Phishing-Resistant by Design
A fake login page can still trick someone into typing a password. It can’t trick a passkey, because a passkey is cryptographically tied to the real site’s domain and simply won’t respond to an impostor one, no matter how convincing it looks.
Where Passkeys Still Fall Short
Adoption is real but uneven. A 2026 academic census of the top 100,000 websites found that 11.3% support passkeys overall – but that figure jumps to 20% among the top 100 sites, the handful of platforms (Google, Microsoft, Apple, major banks and retailers) that most people and businesses actually use every day. Smaller vendors, niche software, and industry-specific portals lag well behind.
In practice, that means passkeys and passwords will coexist for a while yet. The right move isn’t waiting for universal support before starting – it’s turning passkeys on wherever they’re already available, starting with your highest-value accounts (email, banking, core business applications), while keeping a password manager in place for everything that hasn’t caught up.
What We Recommend for Clients
We deploy and recommend Keeper Security across our client base, and it handles both sides of this transition – storing and auto-filling passkeys wherever a site supports them, and managing strong, unique passwords everywhere else, all in one vault. That means employees aren’t juggling two separate tools or reverting to memorized passwords out of convenience. Our advice to clients right now: turn on passkeys for the accounts that support them, especially email and financial logins, and let the password manager handle the rest until the remaining 80-90% of the web catches up.
The Bottom Line
Passkeys aren’t a future technology anymore – over 5 billion are already in active use, and the sites that matter most (email, banking, the platforms your business runs on) are disproportionately the ones that support them. Chick-fil-A’s second breach in four years is what happens when a business treats a stronger login method as optional rather than removing the weak one. Passwords aren’t gone yet, and won’t be for a while, but the businesses ahead of this are the ones turning passkeys on wherever they can today rather than waiting for the other 90% of the web to catch up first.
Book a Free Consultation
Not sure which of your accounts already support passkeys, or how to roll them out for your team? Let’s talk. Book a time on my calendar and we’ll walk through what’s possible today, as part of a broader cybersecurity program built for your business.
Frequently Asked Questions
A passkey is a digital credential that replaces your password rather than adding a step on top of it. Your device proves your identity using cryptography (unlocked with your fingerprint, face, or PIN), so there’s no password transmitted, typed, or stored that an attacker could steal or reuse.
A password is a shared secret you type, which means it can be phished, guessed, leaked, or reused across sites. A passkey never leaves your device and is cryptographically tied to the specific site it was created for, so it can’t be phished, reused elsewhere, or bought off a list of leaked credentials.
Yes. Because there’s no shared secret to steal, passkeys eliminate credential stuffing and password-reuse attacks entirely – the exact attack type behind Chick-fil-A’s 2026 credential stuffing breach. Organizations using passkeys have also reported measurably fewer phishing-related incidents.
Yes, and you’ll need to for a while. A 2026 census of the top 100,000 websites found only 11.3% support passkeys overall, though the figure is much higher (20%) among the most-used sites. A password manager that handles both passkeys and passwords, like Keeper Security, covers the gap.
Yes. It stores and auto-fills passkeys wherever a site supports them, alongside managing strong, unique passwords for everything else, so employees use one tool regardless of which method a given site supports.
Start with your highest-value accounts – email and financial logins first, since those are almost always supported – and expand from there as more of your everyday tools add support. You don’t need to wait for universal adoption to get the security benefit where it’s already available.