{"success":true,"data":{"id":"fake-passkey-account-recovery-override-phish","label":"Fake passkey account recovery override phishing — claims a passkey was removed/revoked and the user must re-enroll via a credential-harvesting recovery URL, exploiting passkey transition confusion. FIDO Alliance Q1 2026; Proofpoint Feb 2026; Krebs Mar 2026.","description":"Emails claiming the recipient's passkey was removed, revoked, or is no longer valid for their account (Apple ID, Google Account, Microsoft Account, GitHub, Coinbase), directing them to re-enroll or \"recover\" their account via a link that harvests credentials by falling back to password + SMS OTP. This is distinct from fido-passkey-downgrade-lure (which detects emails initiating the initial passkey enrollment downgrade). This signal targets the post-enrollment recovery override — the attacker pretends the existing passkey was invalidated and forces a recovery flow. The FIDO Alliance issued a specific Q1 2026 advisory documenting this attack pattern across member organizations; Proofpoint (February 2026) and Sublime Security (March 2026) confirmed active campaigns targeting Apple, Google, and Microsoft users.","tier":"danger","category":"phishing","isThin":false}}