cybersecuritypasskeysphishingmalwarecanadian smb

New Pass-ta-key attacks let malware hijack Google-synced passkeys

August 3, 2026

Back to all posts

Source: BleepingComputer

A new type of attack, named 'Pass-ta-key', has been discovered that allows malware to steal Google-synced passkeys. This attack exploits the Fast Identity Online (FIDO) protocol, a security standard used for authenticating users across various online services, including Google accounts. Malicious actors are using phishing techniques to trick users into installing malware on their devices which then intercepts and hijacks the FIDO authentication process. This poses a significant threat to Canadian businesses as it compromises the multi-factor authentication (MFA) system used to secure sensitive data, potentially leading to data breaches and unauthorized access. To mitigate this risk, Canadian SMB owners and IT managers should ensure their systems are updated with the latest security patches, educate employees about phishing scams, implement a strong password policy, and consider using security solutions that offer protection against such advanced threats.
cybersecuritypasskeysphishingmalwarecanadian smb

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment