Passkeys: what you need to know
EC3 recommends using passkeys instead of passwords wherever they are available.
Passwords can be guessed, stolen in data breaches, or given away in phishing attacks. Passkeys replace them with a cryptographic key that never leaves your device — and can't be tricked out of you.
Why passkeys are safer
Passkeys address the biggest weaknesses of passwords:
- there is no shared secret for criminals to steal from a website
- they can't be entered into a fake phishing site — the key only works on the genuine service
- signing in uses your device's fingerprint, face or PIN, so there is nothing to remember
- they resist credential-stuffing attacks that follow major data breaches
Getting started
Major services across Europe — including banks, email providers and marketplaces — now offer passkeys. Look for 'Create a passkey' in your account's security settings. Your passkeys sync securely across your devices through your platform's password manager, so you won't lose access when you change phone.
If you can't recover your account
In some cases it may not be possible to recover an account. If so, create a new one, tell your contacts you've abandoned the old account, and update any bank, utility or shopping websites with your new details. If the incident involved money or personal data, report it to your national police portal — your report feeds into Europe-wide investigations coordinated by EC3.