Security researchers at Proofpoint have revealed a downgrade attack pathway that can weaken FIDO-based authentication systems, raising concerns about potential phishing and account takeover risks. The vulnerability does not represent a flaw in the FIDO standard itself, but rather stems from implementation gaps in browser and platform support combined with fallback authentication flows.
How the Downgrade Attack Works
The attack uses adversary-in-the-middle (AiTM) techniques, where attackers build fake login portals that trick users into switching away from secure passkey flows. Proofpoint’s proof-of-concept showed how attackers could simulate an unsupported browser environment, such as Safari on Windows, to cause authentication errors. These errors then prompt the user to fall back to less secure options, which can be intercepted by phishing kits or Phishing-as-a-Service platforms. While the attacks have not yet been observed in active campaigns, Proofpoint warns that the availability of sophisticated AiTM kits makes the risk credible.
The concern arises as enterprise deployment of FIDO and passkey authentication continues to expand. According to the FIDO Alliance, 87 percent of surveyed enterprises in the United States and United Kingdom have deployed or are deploying passkeys for employee sign-ins. Large-scale programs such as VicRoads’ rollout of passkeys for nearly 5 million account holders underscore the importance of addressing downgrade vectors before attackers attempt to exploit them.
Mitigation and Wider Security Context
Proofpoint recommends organizations reduce risks by disabling fallback methods where possible, strengthening real-time user agent validation, and adding extra security checks if a fallback path is triggered. Security awareness training is also advised so employees can recognize suspicious login prompts and avoid entering credentials into spoofed portals. The researchers argue that platform and browser vendors must improve FIDO support to close downgrade gaps and make fallback routes unnecessary for most users.
The findings add to a growing list of authentication-related concerns as organizations adopt biometrics and passkeys. Earlier this year, Europol highlighted risks of AI-generated presentation attacks against biometric systems, warning that adversaries are increasingly capable of exploiting weaknesses in identity verification tools. Together, these warnings suggest that even strong standards like FIDO require careful implementation and layered defenses to remain effective against evolving threats.
Although no real-world exploitation has been confirmed, Proofpoint’s research highlights how downgrade techniques could undermine trust in authentication systems if not addressed. As adoption of passkeys accelerates globally, experts caution that enterprises must enforce strict authentication flows and limit reliance on fallback mechanisms to prevent attackers from creating new entry points into sensitive accounts.
Sources: SecurityBrief, IT Brief Asia, IT-Daily, Proofpoint
–
By Ali Nassar-Smith






Follow Us