{"success":true,"data":{"id":"fido-passkey-downgrade-lure","label":"FIDO/passkey downgrade AiTM — \"passkey unavailable, use password/SMS/authenticator instead\" (Proofpoint Evilginx phishlet)","description":"Body frames a passkey, FIDO, WebAuthn, security key, or biometric sign-in as \"temporarily unavailable / not supported / failed\" OR instructs the recipient to remove/reset their passkey and fall back to password, SMS, authenticator app, or OTP — the phish-resistant-auth downgrade pattern pioneered by Proofpoint-documented Evilginx phishlets (Jul 2025). The phishlet spoofs Safari-on-Windows user agents so Entra ID returns a passkey error and falls back to weaker MFA. BleepingComputer, DarkReading, and WorkOS confirmed the attack class. Distinct from oauth-consent-phishing and aitm-session-cookie-phishing-lure which target the surrounding OAuth or session flows.","tier":"danger","category":"other","isThin":false}}