Passkeys in digital banking: how they prevent fraud

Share

In the midst of a boom in digital attacks, passwords—weak, repetitive, forgotten—have become the weakest link in security. According to a global study by the FIDO Alliance, more than 35% of users had at least one account compromised due to vulnerable passwords in the last year, and 47% abandoned a purchase because they forgot their password. This problem is even more pronounced among young people: a study revealed that 42% of users abandoned a purchase in the last month because they couldn’t remember their password, a figure that exceeds 50% among those under 35. Furthermore, in the US, an alarming 87% of consumers have canceled a registration or purchase due to access difficulties, often related to passwords, according to the Small Business Trends website .

Faced with this situation, passkeys, based on public-key cryptography, are emerging as an alternative that not only strengthens security but is also redefining the digital experience.

What are passkeys and how do they work?

Passkeys eliminate reliance on traditional passwords by using a pair of cryptographic keys: a public key (stored on the service) and a private key (securely stored on the user’s device), protected by biometrics or a PIN. According to Specops Software, this architecture allows users to log in simply with their fingerprint, facial recognition, or a local PIN, without needing to remember complex passwords. According to Dashlane, this also reduces login abandonment, as it simplifies the experience and speeds up access.

This mechanism also completely prevents phishing: passkeys only work on the original site or app for which they were created and never transmit reusable credentials. According to Google for Developers, even if a user falls for a fraud attempt, the private key never leaves their device and therefore cannot be intercepted.

Furthermore, adoption is supported by the tech industry giants. According to WIRED, Apple, Google, and Microsoft have already incorporated passkeys into their operating systems and browsers, making them the path to more secure access. And according to the Forbes Tech Council, this effort to consolidate passkeys as a global standard will accelerate the transition to a passwordless future.

The future of digital access: Measurable benefits and sectors that will lead the adoption of passkeys

The benefits of passkeys are already measurable: they reduce phishing attempts by 100%, speed up logins up to four times faster than traditional passwords, and reduce costs associated with credential resets, a major pain point for IT and customer service departments, according to Google and the FIDO Alliance . According to McKinsey , their adoption improves the user experience and increases e-commerce conversion rates by eliminating access friction. This makes them especially ideal for financial services and banking—where account protection is critical—retail and e-commerce, which seek to reduce shopping cart abandonment, and governments or public entities, which require strong authentication for mass and sensitive services.

Passkeys in digital banking

In the financial sector, where phishing attacks and credential theft are major fraud vectors, passkeys offer a critical layer of protection. According to the IBM X-Force Threat Intelligence Index 2024 , more than 70% of global security breaches originate from compromised credentials, a figure that makes traditional passwords a systemic risk.

A digital banking customer accesses their mobile app without having to remember a username and password. Instead, the system validates a passkey protected by their device’s biometrics (fingerprint, face, or secure PIN). The private key never leaves the phone, while the bank only stores the public key, rendering any phishing or brute-force attacks useless.

Benefits for banking:

  • Reducing phishing fraud: Passkeys cannot be reused on fake sites.
  • Improved customer experience: faster and frictionless access, reducing login abandonment.
  • Operational savings: Fewer password reset requests, which Forrester says represent millions of dollars in annual support costs.
  • Regulatory compliance: By strengthening strong authentication, they contribute to standards like PSD2 in Europe or local financial protection regulations in Latin America.

For banking, passkeys not only represent a leap in security, but also an opportunity to build digital trust, streamline access, and reduce operating costs.

An imminent future but with challenges

Passkey adoption is growing rapidly, and more and more services are integrating them, but the road ahead is still not without its obstacles. One of the main problems is that many systems still allow a return to traditional passwords, which reduces the effectiveness of this model and opens up the risk of phishing attacks.

According to TechRadar , another challenge is recovery after a lost or stolen device: although cloud backup mechanisms exist, the user experience remains a sore point. There are also challenges of compatibility across platforms and ecosystems, requiring a global standardization effort. And, perhaps most importantly, there is user education: moving from “remembering a password” to “relying on a biometric method” involves a cultural shift that not all audiences assimilate at the same pace.

Even with these barriers, analysts agree that passkeys represent one of the most robust cybersecurity transformations of the last decade. As the FIDO Alliance points out, the key to their success will lie in the balance between enhanced security, interoperability, and ease of use, factors that will make a difference in critical sectors such as banking, retail, and digital public services.

You may be interested in

The identification iceberg: The invisible structure that supports modern security.

The identification iceberg: The invisible structure that supports modern security.

The identification iceberg: The invisible structure that supports modern security.

Our intelligent identity identification, payment and data protection solutions will evolve the security of your organization.

Let's talk: