Proofpoint Discovers 'FIDO Downgrade' Attack Vulnerability in Authentication Systems

Silhouetted hand casting vote into glowing ballot box, depicting concept of democratic elections or voting process through abstract visual metaphor.

Security researchers at Proofpoint have identified a new authentication security threat called “FIDO downgrade attacks” that can bypass FIDO-based authentication systems by exploiting their fallback mechanisms. The attack uses specialized phishing toolkits known as “phishlets” to force authentication away from secure FIDO methods toward more vulnerable alternatives like SMS codes or one-time passwords.

FIDO authentication, which has seen widespread adoption by major tech companies including Apple, Google, and Microsoft, typically provides strong phishing resistance through hardware security keys, biometrics, or PINs. However, the downgrade attack takes advantage of fallback authentication options that systems provide when FIDO authentication is unavailable. Attackers can spoof browser or device details to convince servers that FIDO-capable devices are not present, triggering less secure backup authentication methods.

The attacks are executed through phishlets that function as adversary-in-the-middle (AiTM) proxies, creating fake login portals that can intercept authentication credentials and tokens. The technique bears similarities to recent OAuth phishing campaigns that have successfully bypassed Microsoft 365’s MFA protections, enabling session hijacking without requiring the attacker to compromise the actual FIDO passkey.

While Proofpoint researchers have not yet detected these downgrade attacks being used in real-world incidents, they indicate that sophisticated threat actors, including state-sponsored groups and advanced persistent threats (APTs), may adopt this technique as FIDO adoption increases. The concern is particularly relevant as organizations worldwide are rapidly transitioning to passkey-based authentication systems.

“It is important to note that FIDO-based passkeys remain a highly recommended authentication method to protect against prevalent credential phishing and account takeover (ATO) threats,” Proofpoint researchers stated.

To mitigate risks from potential downgrade attacks, security experts recommend that organizations strengthen their browser and platform support for FIDO authentication while carefully managing and limiting fallback authentication methods. Organizations should particularly scrutinize situations where alternative authentication methods are used as backups. These recommendations support recent CISA guidelines emphasizing the importance of robust FIDO authentication implementations in mobile security frameworks.

The discovery of this vulnerability comes as major enterprises like Thales and HID Global are launching new enterprise-grade passkey management solutions, highlighting the growing need for secure, scalable authentication systems that can resist sophisticated attack methods while maintaining usability.

Sources: IT Brief Asia, Security Brief, Integrator Media, WebProNews, Red Hot Cyber