UK Government Cyber-Attacks Target 23 Million Users, Forcing Password Phase-Out
Key Takeaways The UK government has begun implementing passkeys for its GOV.UK One Login system, impacting over 23 million users. This initiative introduces a passwordless authentication method,...
Key Takeaways
- The UK government has begun implementing passkeys for its GOV.UK One Login system, impacting over 23 million users.
- This initiative introduces a passwordless authentication method, leveraging biometric scans or device PINs for accessing public services.
- The move aims to enhance security against phishing attacks and improve user convenience, while also generating significant operational savings.
- Passkeys are optional, with traditional password and two-factor authentication remaining available as a fallback.
The United Kingdom government has initiated the rollout of passkeys across its GOV.UK One Login platform, providing a passwordless authentication method for more than 23 million citizens accessing public services. This strategic shift is designed to streamline user access while bolstering security against prevalent cyber threats.
Table Of Content
This widespread deployment encompasses a diverse array of essential government services, from managing State Pensions and tax affairs to applying for childcare support and renewing driving licenses. The transition fundamentally alters the authentication experience for citizens interacting with government digital systems.
Rather than inputting a traditional password followed by a one-time code received via text message, users can now authenticate using the same biometric data—such as a fingerprint or facial scan—or device PIN/pattern they employ to unlock their personal smartphones, tablets, or computers.
UK Government Embraces Passwordless Authentication
Government officials highlight that passkey authentication offers a significantly faster login experience, estimated to be up to eight times quicker than the previous username, password, and two-step verification process.
This extensive implementation follows a successful pilot program where over 300,000 individuals seamlessly adopted passkeys, according to an official announcement published by GOV.UK. The early adoption has been robust, with nearly 10% of all daily GOV.UK One Login authentications now utilizing passkeys. This shift has also led to tangible financial benefits, reducing SMS verification costs by approximately £600 each day.
Enhanced Security Through FIDO2 Standard
From a cybersecurity standpoint, passkeys are a significant upgrade, directly addressing numerous vulnerabilities inherent in password-based authentication. Built upon the FIDO2 standard, these cryptographic credentials are securely linked to the specific legitimate website and are managed by a trusted device or dedicated credential manager.
This architectural design renders passkeys exceptionally resilient to common credential-phishing attacks. Since users do not possess a reusable password to inadvertently disclose on a fraudulent login page, the primary vector for such attacks is effectively mitigated. The National Cyber Security Centre (NCSC) affirms that passkeys are immune to interception, reuse, or theft in the same manner as passwords, strongly advocating for their use wherever supported.
It is important to note that biometric information, such as fingerprints or facial templates, or PINs, are used exclusively for local authorization of the credential on the user’s device. GOV.UK One Login does not receive or store any of this sensitive biometric data.
Passkeys offer flexibility, allowing synchronization through a device’s credential manager. Furthermore, users can authenticate on a different device by scanning a QR code with a nearby device that holds the passkey.
Optional Adoption and Important Considerations
The introduction of passkeys does not immediately eliminate passwords. Passkeys remain an optional choice for users, who can continue to sign in with their existing password and security code. This traditional method also serves as a fallback option should a passkey become unavailable for any reason.
GOV.UK advises against setting up a passkey on shared devices, as anyone with the ability to unlock that device could potentially gain access using the stored credential.
Stephanie Peacock, the Digital Government Minister, emphasized that this technology will enable rapid access to crucial services while simultaneously strengthening defenses against fraudsters targeting passwords. Echoing this sentiment, Jonathon Ellison, NCSC Director for National Resilience, characterized passkeys as a “highly phishing-resistant alternative,” encouraging citizens to activate them on GOV.UK One Login and other compatible services.
For the government, this migration represents a dual benefit: measurable operational savings combined with a reduction in authentication friction. For users, it alleviates password fatigue and reduces reliance on often inconvenient SMS codes. However, as password-based recovery mechanisms persist, the overall security of accounts will, to some extent, continue to rely on the robust implementation and protection of these fallback options as passkey adoption expands.
What You Should Do
- Enable Passkeys: If you use GOV.UK One Login, consider activating passkeys for enhanced security and a faster login experience.
- Use on Personal Devices: Set up passkeys only on devices that you exclusively control and that are secured with your unique biometric or PIN.
- Understand Fallback Options: Be aware that passwords and traditional two-factor authentication remain available as backup methods.
- Stay Informed: Regularly check official GOV.UK guidance for best practices and updates regarding passkey usage.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.