Smartphone fingerprint sign-in for mobile banking security
Photo by Pixabay on Pexels

For years, the advice on protecting your bank account sounded simple. Use a strong password and turn on two-factor authentication, so the bank texts you a six-digit code whenever you log in from a new device. That advice still beats nothing. But the text-message code has turned into one of the main things criminals go after, and a newer login method called a passkey is showing up in more banking apps. If you’ve seen a prompt asking whether you want to “sign in with a passkey” and weren’t sure what that means, this is for you.

What a one-time passcode is, and why it was a big improvement

A one-time passcode, or OTP, is the short code your bank sends by text or email, or that an authenticator app generates. The idea is that a password alone is something you know, and anyone who steals it can use it. Adding a code sent to your phone means the thief also needs something you have. That’s the “two” in two-factor.

For a long time this worked well against the most common attack, which was someone buying leaked passwords in bulk and trying them on bank websites. A stolen password without the matching phone got them nowhere.

The weak spot: codes can be handed over

The problem with a code is that it’s just a number, and a number can be read aloud, typed into the wrong website, or intercepted. Criminals figured out that the easiest way to get one is to ask for it.

The FBI laid this out in a November 2025 public service announcement on account takeover fraud. Scammers call, text, or email while pretending to be your bank’s fraud department or tech support. They might say there’s a suspicious charge on your account, then ask you to “verify” yourself by reading back the code that just arrived. Meanwhile, they’re logging into your account on the other end, and your code is the last thing they need. Once inside, they often reset the password, lock you out, and move the money quickly, frequently into accounts tied to cryptocurrency wallets where it’s hard to trace. The FBI said it had received more than 5,100 account takeover complaints since January 2025, with losses above $262 million.

The same announcement describes fake bank websites promoted through paid search ads, a trick the FBI calls SEO poisoning. You search for your bank, click the top result, and land on a convincing copy of the login page. You type your password and the code, and the criminal relays both to the real site in real time. The FBI’s own wording is blunt: multi-factor authentication “will not protect you if you land on a fraudulent login page.”

So OTPs guard well against a stolen password sitting in a database. They’re weak against a person who can talk you, or trick you, into handing the code over.

How a passkey is different

A passkey replaces the password and the code with a pair of cryptographic keys. When you create one, your phone or computer makes two linked keys. The public key goes to your bank. The private key stays on your device (or in your password manager or phone’s keychain, if it syncs), and you unlock it with your fingerprint, your face, or your device PIN.

When you sign in, the bank sends a challenge, your device signs it with the private key, and the bank checks the signature using the public key it already has. You never type anything secret. There is no code to read aloud and no password to reuse.

The part that matters most for fraud is that each passkey is tied to the exact website or app it was created for. If you end up on a lookalike site, even a perfect copy, your device won’t offer the passkey, because the web address doesn’t match. The fake site has nothing to steal, and a caller claiming to be from your bank has nothing to ask you for. That’s what security people mean when they call passkeys “phishing resistant.”

Why regulators and standards bodies are paying attention

The National Institute of Standards and Technology, which writes the federal government’s digital identity guidelines, finalized a major update in July 2025. NIST SP 800-63B-4 requires services at its middle assurance level to offer a phishing-resistant sign-in option, and it now explicitly accounts for syncable passkeys, the kind that back up to your phone’s cloud account. SMS codes are not considered phishing resistant. These guidelines are written for federal agencies, not your bank, but banks and their regulators tend to follow NIST’s lead on what counts as strong authentication.

In practice, U.S. banks and credit unions are rolling passkeys out at different speeds. Some offer them in the mobile app, some on the website, some not yet. Most still keep text codes around as a backup, which is worth knowing, because an account is only as strong as the weakest sign-in method it still accepts.

Passkeys aren’t magic

Passkeys fix the specific problem of stolen and phished credentials. They don’t stop every scam. If someone convinces you to send money yourself, through a wire, Zelle, or a transfer to a “safe account,” no login method will help, because you’re the one logging in. That kind of authorized payment fraud is harder to recover from than an unauthorized one.

There’s also the question of what happens if you lose your phone. Passkeys that sync through Apple, Google, or a password manager can be restored on a new device once you sign back into that account. That makes it very important to secure the account your passkeys live in, since it’s now holding the keys to more than one door. A device-bound passkey, such as one on a physical security key, won’t sync, so you’d want a second key or another sign-in method set up in advance.

What to do with your own accounts

If your bank offers passkeys, turning them on is a reasonable move for most people. You’ll usually find the option in the app’s security or sign-in settings. Set it up on the devices you use regularly, and make sure your phone itself has a strong passcode, since that passcode now protects your bank login too.

Whether or not your bank supports passkeys yet, the FBI’s other advice still applies. Bookmark your bank’s login page instead of searching for it. Treat any unexpected call from “your bank” as suspect, hang up, and call the number on the back of your card. No legitimate bank employee needs you to read them a login code.

And if something does go wrong, speed matters. The FBI recommends contacting your bank right away to ask for a recall or reversal of any transfer and reporting the incident at ic3.gov. The CFPB also has guidance on your rights when money leaves your account without your permission.

By Olivia

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x