Skip to main content
European CyberCrime Centre
Guidance

Passkeys: what you need to know

EC3 recommends using passkeys instead of passwords wherever they are available.

Illustration for Passkeys: what you need to know
EC3 illustration

Passwords can be guessed, stolen in data breaches, or given away in phishing attacks. Passkeys replace them with a cryptographic key that never leaves your device — and can't be tricked out of you.


Why passkeys are safer

Passkeys address the biggest weaknesses of passwords:

  • there is no shared secret for criminals to steal from a website
  • they can't be entered into a fake phishing site — the key only works on the genuine service
  • signing in uses your device's fingerprint, face or PIN, so there is nothing to remember
  • they resist credential-stuffing attacks that follow major data breaches

Getting started

Major services across Europe — including banks, email providers and marketplaces — now offer passkeys. Look for 'Create a passkey' in your account's security settings. Your passkeys sync securely across your devices through your platform's password manager, so you won't lose access when you change phone.


If you can't recover your account

In some cases it may not be possible to recover an account. If so, create a new one, tell your contacts you've abandoned the old account, and update any bank, utility or shopping websites with your new details. If the incident involved money or personal data, report it to your national police portal — your report feeds into Europe-wide investigations coordinated by EC3.

Back to top