SOC2Prep

Passkey enrolment is the new phishing target

September 15, 2026. From issue 6 of The Compliance Brief, one story for teams preparing for a first SOC 2 audit.

Last reviewed 2026-09-15Written by Jacob Masse, TrazTech Inc.

Issue 6 of The Compliance Brief went to subscribers on September 15, 2026. One of its 5 stories bears on the controls a SOC 2 audit tests, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: The Hacker News

Microsoft detailed two campaigns abusing third-party email delivery infrastructure. One sent over a million scam messages between August 3 and 5, 2026, impersonating chief executives.

Our take, in short

Plenty of readers have told a US prospect that they moved to passkeys and are therefore phishing-resistant. That claim holds for the authentication step and falls apart at registration and account recovery, which is exactly where these campaigns are aiming.

Read the full take on traztech.ca

Also in issue 6

Outside the controls a SOC 2 audit tests, but in the same email:

Older: issue 4 All issues on SOC2Prep Newer: issue 7