Start with Identity
This Week in Identity · Issue 13 · 2026-09-15 · Covers 2026-09-09 to 2026-09-15

This Week in Identity, Issue 13

Issue 13 of This Week in Identity. Passkeys had their biggest government deployment and their most cynical attack in the same week.

In brief

  • GOV.UK One Login opened passkeys to more than 23 million users, already saving close to 600 pounds a day in SMS costs, with passwords still optional.
  • Attackers are calling employees on their personal phones, posing as IT, and telling them to update their passkey settings. The passkey is the pretext, not the target.
  • Okta found 1,843 still-unexpired session tokens in a single 7GB infostealer dump, including live API keys for four AI providers.

The big story

The UK opened passkeys to 23 million users, and the interesting part is the arithmetic it published. GOV.UK One Login extended passkey support across childcare, driving licences, State Pension and tax services after a 300,000-user trial. Nearly one in ten daily sign-ins already use one, the government puts them at up to eight times faster than password plus 2FA, and the shift is saving close to 600 pounds a day in SMS.

Steal the SMS figure for your own business case. Every organization still sending one-time codes is paying a per-message bill for its weakest factor, and that is the rare security argument a finance team will engage with. Amazon reported similar economics at 175 million users in August.

But read the "killing off passwords" framing carefully, because it has not happened. Passkeys are optional and passwords remain, which means every One Login account keeps a phishable recovery path, in the same week a kit that disables WebAuthn to force exactly that fallback was documented at 258 organizations. A passkey next to a live password is a faster login, not a phishing-resistant account. That is less a criticism than a description of where the hard part begins: removing the fallback at 23 million users means solving recovery for people with one device and no backup, which nobody has solved at population scale. Watch what the UK announces about recovery next. Source: GOV.UK One Login opens passkeys to 23 million.

Patch this week

  • CVE-2026-86218, N-able N-central (CVSS 10.0). Pre-auth RCE, exploited in the wild, fourth hotfix in five weeks. CISA set a federal deadline of September 11. Post.
  • CVE-2026-20079, Cisco Secure FMC (CVSS 10.0). Unauthenticated root, used to deploy web shells that query internal databases for credentials. KEV deadline September 12. A second flaw, CVE-2026-20316, is how Qilin gets in. Post.

The pattern

Three stories this week end in a credential store nobody classified as one. Cisco FMC holds the RADIUS and LDAP bind accounts, so root on the console is a credential harvest rather than a foothold. An exposed LiteLLM gateway holds every provider key the applications behind it would otherwise each carry. An infostealer log holds live sessions for a dozen services at once. Inventory work usually stops at the systems that authenticate users; the higher-value targets are increasingly the systems that hold the credentials for other systems. See credential manager key extraction and static API key abuse.

What else happened

  • Attackers are phoning employees about their passkeys. Microsoft detailed a campaign running since May: reconnaissance from social media, a call to the personal phone posing as IT, an SMS link to a fake Microsoft sign-in, then the attacker registers their own authentication method for persistence. A workforce told to expect authentication changes is primed to comply with a fake one, so tell people now how you will and will not contact them. Post.
  • Okta analysed a 7GB infostealer dump from 5,871 machines: 44,791 JWTs, 1,843 still unexpired on release day, 24 live API keys for Gemini, OpenAI, Groq and OpenRouter, and 17.7 percent of JWTs carrying plaintext PII. A JWT is signed, not encrypted, so whatever is in the payload belongs to whoever holds the token. Post.
  • Nearly one in ten exposed LiteLLM gateways accept sk-1234, the key from the setup docs, and 191 had no key at all, which defaults to full admin. Same failure as the JFrog phantom join key the week before: a default that fails open. Post.
  • The McKesson breach resolved to 6.4 million people, against the 284 million records claimed. The gap is the lesson: extortion groups quote row counts, and the first number to reach a headline is the attacker's. Post.

New from Start with Identity

  • 15 news posts and a queue cleared to zero, each skip carrying a recorded reason.
  • Three new CVE briefs and the technique library cross-links behind them at /cves/ and /techniques/.

From the community

We are recruiting volunteers: news curators, country ambassadors, and jobs scouts. A few hours a week, credited by name.

That's Issue 13. Subscribe for the next one.

Free to read and share. Independent and community-driven, no sponsorship. Subscribe to get the next issue.