> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# UK.gov begins killing off passwords for 23 million users
- URL: https://f4n6.co.uk/security-feed/uk-gov-begins-killing-off-passwords-for-23-million-users/
- Published: 2026-09-14T14:31:42.000Z
- Updated: 2026-09-14T14:31:42.000Z
- Author: Jeff Davies
- Tags: #security-feed

## 1\. Executive summary

The UK government has expanded passkey authentication across GOV.UK One Login to a user base of more than 23 million, following a trial with over 300,000 users; passkeys are now used for nearly one in ten daily One Login sign-ins and remain optional, with password-plus-SMS-2FA still supported. The change is a defensive posture improvement, not a security incident: passkeys are phishing-resistant credentials bound cryptographically to the relying party, and the biometric or PIN unlock never leaves the user's device. There is no CVE, no exploitation activity and no threat actor in this item — no VERIFIED REFERENCE DATA (CVSS, severity, CISA-KEV state) was resolved for it, and none is asserted here. For EMEA financial services clients the direct risk is negligible; the material relevance is strategic — it is a large-scale, government-backed reference case for phishing-resistant authentication that clients can cite in their own MFA and customer-authentication roadmaps. The residual exposure is that passwords and SMS OTP remain enabled, so the legacy phishing and OTP-relay threat model is not retired, only diluted.

## 2\. Regulatory framing

No specific DORA/NIS2 article is directly engaged by this item.

This is a voluntary authentication-modernisation rollout on a UK public-sector identity service. There is no ICT-related incident, no third-party ICT provider relationship created or changed for an EMEA financial entity, and no supply-chain event described in the source. Mapping DORA Art. 17/18/19 (incident management, classification, reporting), DORA Art. 28–30 (ICT third-party risk) or NIS2 Art. 21(2)(d)/23 to a government passkey announcement would be compliance-checkbox padding, not analysis.

One conditional note, offered as guidance rather than as an engaged obligation: if a client integrates GOV.UK One Login into a customer onboarding, identity-proofing or entitlement flow, the authentication mechanism of that dependency is changing and should be reflected in the client's own third-party and change-management records. The source does not state that any financial services firm uses One Login, so this is a self-assessment prompt, not a finding.

## 3\. Technical analysis & attack chain

This item is a strategic/policy development. There is no attack chain to reconstruct — the source describes no intrusion, no exploited component and no adversary. What follows is the fraud model the rollout is designed to defeat, drawn from the source, plus a clearly-labelled Adverse Trace assessment of what remains exposed.

**The credential-phishing model passkeys address.** The source frames the problem as follows: cyber criminals look for the easiest route into important accounts, and login details remain a common target (Jonathon Ellison, director for national resilience, NCSC). The specific mechanics named are: a password that can be stolen, reused, or handed over to a convincing fake login page; and a second factor delivered as a one-time code that the user waits for and then types. That combination — reusable shared secret plus relayable OTP — is what conventional phishing kits and adversary-in-the-middle proxies monetise.

**How passkeys change the mechanism.** A passkey is a cryptographic credential tied to the specific website or application for which it was created. The fingerprint, face scan or device PIN used to unlock it stays on the user's device and is not seen or stored by GOV.UK One Login. The practical consequence is that there is no shared secret to phish and no code to relay to an attacker-controlled session: a credential minted for the genuine relying party will not authenticate against a lookalike domain.

**Deployment facts from the source.** Rollout follows a trial of more than 300,000 users. Scale is 23 million-plus One Login users. Adoption is approximately 10 percent of daily sign-ins. The government claims passkeys are up to eight times faster than username + password + 2FA. The government states the switch is already saving nearly £600 per day in SMS costs. Passkeys are optional; password sign-in remains available. One Login is used for checking State Pension details, managing tax services and accessing childcare support.

**Adverse Trace assessment (analyst inference, not source fact).** Three residual exposures follow from the source's own framing and should be tracked by anyone treating this as a template:

1. **Optional means both paths stay live.** Because passwords remain enabled, the phishing surface is reduced but not removed. Attackers optimise toward the weakest accepted path, so the legacy flow remains the target of record until it is deprecated.
2. **Account recovery becomes the pressure point.** The source does not discuss recovery or enrolment flows. Historically these are where phishing-resistant authentication is bypassed, because recovery re-introduces a phishable factor. Treat this as an open question to put to any vendor or identity team citing passkey adoption as a control.
3. **SMS OTP cost reduction is a proxy metric, not a security metric.** The £600/day saving is a useful adoption signal but says nothing about coverage of high-risk transactions or about step-up authentication on sensitive actions.

No malware, persistence mechanism, C2 channel, lateral-movement technique or exfiltration path is described in the source, and none is asserted.

## 4\. Mitigation & containment

This item requires no emergency response. The actions below are process and roadmap controls, not containment.

### P1 — within 24 hours

- Confirm whether any customer-facing or workforce authentication flow in your estate depends on GOV.UK One Login (onboarding, identity proofing, entitlement checks, UK public-service integrations). If yes, log the authentication-mechanism change against that dependency in your third-party and change-management records and confirm with the owning team that passkey enrolment does not break existing session or assertion handling.
- If no dependency exists, no action. Do not raise an incident.

### P2 — within 72 hours

- Where you operate consumer or workforce authentication, use this rollout as a forcing function to review your own phishing-resistant MFA position: which populations are still on password + SMS OTP, and which high-risk actions (payments, payee creation, credential or contact-detail change) still accept a phishable factor.
- Ask identity vendors and integrators for their passkey/FIDO2 roadmap and, specifically, how account recovery and device-loss re-enrolment are handled. Recovery is the control that determines whether passkey adoption actually reduces phishing loss.

### P3 — within 7 days

- Add passkey adoption rate and residual password/OTP sign-in share to your authentication risk reporting, so the metric tracks coverage rather than headline enablement.
- Brief fraud and customer-operations teams that a government-scale passkey deployment is now live, so that "we use passkeys" is not accepted as a blanket assurance in vendor or partner due diligence without evidence of recovery-flow design.

There is no vendor patch, version pin, registry key, file path or firewall rule associated with this item. None is fabricated here.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

The source describes no malicious infrastructure, no hashes, no domains, no file artefacts and no adversary behaviour. It describes a legitimate authentication change on a government identity service. There are therefore no atomic indicators and no behavioural indicators of threat activity to publish; the authentication-pattern observations in §3 are a description of a defensive control, not of attacker behaviour, and are deliberately not presented as detection content.

## 6\. Detection

Insufficient indicators to author detection rules.

No threat artefacts — no strings, command lines, mutexes, scheduled tasks, service names, file paths, registry keys or ransom-note text — are present in the source. Authoring a YARA or Sigma rule from this item would mean detecting reporting about a policy change rather than detecting a threat.

## 7\. Sources

- The Register — "UK.gov begins killing off passwords for 23 million users" — https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088 — 2026-09-14
- The related source supplied with this item is the same Register article (identical URL and content); it provides no independent corroboration.

## 8\. Adverse Trace position

**Severity:** Informational. No CVE, no CVSS score, no severity rating and no CISA-KEV exploitation state were resolved for this item, and Adverse Trace does not assign one — there is no vulnerability or exploitation activity to rate. **Confidence:** the factual claims (23 million users, 300,000-user trial, \~10 percent of daily sign-ins, £600/day SMS saving, 8x speed claim) rest on a single source, The Register, reporting statements by the UK government and NCSC; the adoption and cost figures are government-supplied and unaudited. Treat as single-sourced; verify before citing in client-facing material. No attribution is made and none is possible — no actor is named in the source. **Client impact:** low and indirect for EMEA financial services. This is a defensive improvement on a UK public identity service, not a threat to client estates. Its value to clients is as a reference case for phishing-resistant authentication and as a prompt to examine their own recovery flows and residual password/OTP exposure. **Next:** Adverse Trace will not issue follow-up tracking on this item unless the rollout is accompanied by a reported authentication bypass, recovery-flow abuse, or a change to the One Login integration contract surface that affects financial-sector relying parties. Clients integrating GOV.UK One Login who want their dependency reviewed should raise it through their usual channel.

---

[Read the original source →](https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*