Microsoft is intensifying its push toward passwordless security, warning that traditional passwords and older forms of two-factor authentication are becoming increasingly ineffective against modern phishing attacks powered by artificial intelligence.
In a statement released during World Passkey Day, Microsoft said the cybersecurity industry must reduce dependence on passwords and other “phishable” login methods by accelerating the adoption of passkeys.
For years, technology companies encouraged users to strengthen account security by enabling two-factor authentication (2FA) or multi-factor authentication (MFA). Microsoft itself previously stated that MFA could block more than 99% of password-based attacks. However, cybercriminals have steadily adapted their tactics, particularly targeting SMS-based authentication systems through phishing pages, SIM-swapping schemes, session hijacking, and social engineering attacks.
The company now argues that passwords, even when paired with weak MFA methods like text-message verification codes, continue to leave accounts vulnerable. Microsoft described these older protections as “legacy” authentication methods that can still become entry points for attackers.
Instead, Microsoft is promoting passkeys, which rely on cryptographic authentication rather than memorized passwords. A passkey stores a private digital key directly on a user’s device and only works on the legitimate website or application where it was created. Access is then confirmed through biometric verification, such as fingerprints or facial recognition, or through a device PIN.
Security experts say this approach makes phishing significantly harder because passkeys cannot be reused on fake websites designed to imitate legitimate login pages. Unlike passwords or SMS codes, the authentication process is tied directly to the original domain.
Microsoft also stressed that enabling passkeys alone is not enough if passwords and fallback authentication methods remain active on accounts. According to the company, weak backup options can still be exploited even after stronger protections are introduced. Microsoft has therefore continued removing older authentication systems across its ecosystem, including plans to eliminate security questions from password reset flows beginning in 2027.
The urgency surrounding this transition has increased alongside the rapid growth of AI-generated phishing campaigns. Microsoft cited internal findings showing that AI-assisted phishing operations can achieve click-through rates as high as 54%, meaning more than half of targeted users may interact with malicious messages.
Industry-wide adoption of passkeys is also accelerating. The FIDO Alliance estimates that more than five billion passkeys are already in use globally. Microsoft said hundreds of millions of users now sign into services such as OneDrive, Xbox, and Copilot using passkeys every day.
Internally, Microsoft claims that over 99% of users within its environment now have access to phishing-resistant authentication methods. The company added that account recovery systems remain a critical security challenge because attackers increasingly target recovery processes instead of direct logins.
Researchers and government agencies are broadly supporting the move toward passwordless security. The United Kingdom’s National Cyber Security Centre recently encouraged organizations and consumers to adopt passkeys, citing growing risks from AI-driven phishing and phishing-as-a-service platforms.
Still, cybersecurity researchers caution that passkeys are not completely immune to attack. Recent academic research examining FIDO2 authentication methods found that while passkeys substantially raise the difficulty for attackers, sophisticated compromise techniques involving infected devices, session theft, or manipulated browser environments may still pose risks under certain conditions.
Microsoft maintains that removing passwords and other phishable credentials remains essential as AI systems increasingly act on behalf of users across enterprise environments. If a single digital identity is compromised, attackers could potentially exploit connected AI agents to access systems, trigger workflows, and operate with existing permissions at machine speed.
The Election Commission of India (ECI) said its digital election infrastructure faced more than 68 lakh malicious online hits on the day votes were counted for the recently concluded Assembly elections, with attempts originating from both domestic and overseas sources. According to election officials, the attacks targeted several online systems operated by the Commission, including the public election results portal, but were contained using existing cybersecurity protections.
Officials stated that despite the unusually high volume of hostile traffic, there was no disruption to counting operations or public access to election-related services.
The attacks were directed at ECINET, the Commission’s integrated election management platform that now combines over 40 separate election applications and digital portals into a unified system. The platform is used to manage multiple election-related functions, including monitoring, reporting, voter services, and administrative coordination.
On counting day, May 4, ECINET reportedly processed an average of nearly 3 crore hits every minute. Across all polling phases conducted on April 9, 23, and 29, the platform recorded a total traffic load of 98.3 crore hits, reflecting the scale at which India’s election infrastructure now operates digitally.
The Commission officially launched ECINET in January 2026 after testing its beta version during the Bihar Assembly elections in November 2025. Since then, the application has crossed 10 crore downloads, indicating rapid adoption among election officials, staff, and users accessing poll-related information and services.
Election authorities said the platform played a major operational role during the elections across five states and Union Territories, along with bypolls conducted during the same period. According to officials, ECINET enabled real-time monitoring of election activities, accelerated reporting processes, and improved administrative coordination between different election units. Authorities also said the centralized system helped increase transparency by reducing delays in communication and data sharing.
Cybersecurity analysts have repeatedly warned that election infrastructure has become an increasingly attractive target for malicious cyber activity because such systems process large amounts of real-time public information under intense public scrutiny. During counting periods, election portals often experience massive spikes in traffic as citizens, media organizations, and political workers continuously refresh result dashboards. Security researchers note that these high-traffic periods can also create opportunities for malicious actors to disguise harmful requests within normal user activity.
While the Election Commission did not disclose the technical nature of the 68 lakh malicious hits, such traffic typically includes automated bot requests, denial-of-service attempts, malicious scanning activity, or repeated unauthorized access attempts aimed at slowing systems or overwhelming servers.
The Commission also introduced a new QR code-based photo identity verification system for counting centres during the election process. On counting day alone, more than 3.2 lakh QR codes were generated through ECINET to regulate entry into counting venues. Officials said the system was introduced to ensure that only authorized personnel could enter restricted areas, reducing the possibility of unauthorized access at highly sensitive counting locations.
According to the Commission, this was the first time the QR-based access system had been deployed across all five states and Union Territories simultaneously. The ECI has now decided to adopt the system as a standard security measure for future Lok Sabha and state Assembly elections.
The increasing dependence on centralized digital infrastructure has pushed election management beyond traditional ballot security into the broader domain of cybersecurity, network resilience, identity verification, and real-time system monitoring. As more election operations move onto integrated digital platforms, experts say continuous monitoring and infrastructure hardening will become essential to maintaining uninterrupted electoral processes at national scale.
Several Ubuntu users reported problems installing updates and downloading packages after parts of Canonical’s infrastructure were disrupted during a Distributed Denial of Service (DDoS) attack. Canonical, the company behind the Ubuntu Linux distribution, confirmed that its online systems had been targeted.
In a statement released during the outage, Canonical said its web infrastructure was facing what it described as a sustained cross-border cyberattack and that teams were working to restore affected services. The company added that further updates would be shared through official channels once more information became available.
Discussions across Ubuntu community forums suggested that multiple services were affected during the incident, including Ubuntu’s security API and several Canonical-operated websites. Users also stated that software installations and system updates were temporarily unavailable or failing to complete properly.
Responsibility for the attack was later claimed by a group calling itself “The Islamic Cyber Resistance in Iraq 313 Team.” In Telegram posts attributed to the group, the attackers allegedly said they used a DDoS-for-hire platform known as “Beamed” to carry out the operation.
Beamed is described as a “booter” or “stresser” service, which are platforms that allow customers to pay for DDoS attacks. These services are often advertised as tools for testing website traffic capacity, although security researchers have repeatedly linked them to disruptive cyber operations. According to claims associated with the platform, Beamed is capable of generating attacks reaching 3.5 terabits per second, enough traffic to overwhelm major online infrastructure.
A DDoS attack works by flooding a server or network with enormous volumes of internet traffic from large numbers of connected devices at the same time. Once systems become overloaded, legitimate users may no longer be able to access websites, applications, or online services. Unlike ransomware campaigns or data breaches, the primary goal of most DDoS attacks is to interrupt availability rather than steal information directly.
To create these attack networks, threat actors typically compromise internet-connected devices using malware. Weak passwords, exposed systems, outdated software, and poorly secured smart devices are commonly targeted. Once infected, the devices become part of a botnet that can be remotely controlled through centralized management panels.
Access to these botnets is frequently sold through underground marketplaces and subscription-based services. Depending on the size and duration of the attack, prices can range from as little as $10 for lower-powered services to hundreds of dollars per month for larger and more persistent attacks.
The disruption drew attention within the open-source community because Ubuntu infrastructure is widely used across enterprise servers, development environments, cloud systems, and research institutions worldwide. Problems affecting package repositories or security update services can delay software deployments and patch management for organizations that rely on Ubuntu systems daily.
The incident also reflects how accessible DDoS-for-hire services have become over the past few years. Platforms offering attack infrastructure continue to reduce the technical barrier required to launch disruptive cyberattacks, allowing even low-skilled actors to rent large-scale attack capabilities for relatively small amounts of money.