🔐 Passkey Statistics 2026: 52 Data-Backed Facts on Passwordless Adoption
These passkey statistics are drawn from primary sources published in 2024, 2025 and 2026: the FIDO Alliance Passkey Index and World Passkey Day data, Google, Amazon and Microsoft platform disclosures, the Verizon Data Breach Investigations Report, the FBI Internet Crime Complaint Center (IC3), NordPass, LastPass and NIST. Every figure is attributed inline so journalists, researchers and AI assistants can cite the original.
They answer four questions: how fast passkeys are being adopted, who is leading, how well they perform against passwords, and why the shift is happening now. Where a number depends on methodology or sample, the source and year are stated so you can verify it.
Key Passkey Statistics at a Glance
The Scale of Passkey Adoption
Passkeys crossed from novelty to mass adoption in 2025. The figures below come from the FIDO Alliance, whose World Passkey Day and Passkey Index reports aggregate deployment data from its member companies and public disclosures.
- More than 15 billion online accounts now support passkeys — roughly double the number a year earlier. (FIDO Alliance, 2025)
- Over 1 billion people have activated at least one passkey. (FIDO Alliance, 2025)
- The FIDO Alliance estimates around 5 billion passkeys are in active use worldwide. (FIDO Alliance, 2025)
- Passkeys are now used for roughly 1.3 billion authentications every month — about double the figure a year earlier. (FIDO Alliance, 2025)
- Consumer awareness of passkeys has reached about 75%, up from roughly 39% in 2022. (FIDO Alliance consumer research, 2025)
- 48% of the top 100 websites now support passkeys — more than double the share in 2022. (FIDO Alliance / industry data, 2025)
- Overall passkey use roughly doubled year over year across major consumer platforms. (FIDO Alliance, 2025)
- The global passwordless-authentication market grew from $18.36 billion in 2024 to an estimated $21.81 billion in 2025. (Straits Research, 2025)
Big Tech Leads: Google, Amazon and Microsoft
The largest consumer platforms drive most passkey activity. These figures come directly from each company’s own disclosures.
- Over 800 million Google accounts now use passkeys. (Google, 2025)
- Google has recorded more than 2.5 billion passkey sign-ins over roughly two years. (Google, 2025)
- Google passkey authentications grew 352% after passkeys became a default sign-in option in late 2023. (Google, 2025)
- Google measures a roughly 30% higher sign-in success rate with passkeys than with passwords. (Google, 2025)
- Passkey sign-ins are about 20% faster than password sign-ins on Google. (Google, 2025)
- Google alone accounts for roughly half of all measured passkey activity. (FIDO Alliance / industry data, 2025)
- More than 175 million Amazon customers now use passkeys to sign in. (Amazon, 2025)
- Amazon says passkey sign-in is up to six times faster than signing in with a password. (Amazon, 2025)
- In May 2025 Microsoft made passkeys the default sign-in method for all new Microsoft accounts. (Microsoft, 2025)
- Microsoft’s change extended passwordless support to more than 15 billion accounts across its ecosystem. (Microsoft, 2025)
- Microsoft reports a 98% success rate for passkey sign-ins, versus just 32% for passwords. (Microsoft, 2025)
- More than 99% of users who sign into a Windows device with a Microsoft account do so with Windows Hello. (Microsoft, 2025)
How Passkeys Perform vs Passwords
Adoption is driven by hard numbers on speed, success and support cost. These come from the FIDO Alliance Passkey Index (2025), which surveyed enterprises deploying passkeys at scale.
Data visualisation: a horizontal bar chart comparing login success rates. Passkeys succeed on 93% of sign-in attempts versus 63% for passwords and other traditional methods — a 30-percentage-point gap. In the same dataset, passkeys cut average sign-in time by 73% (8.5 seconds versus 31.2 seconds).
- Passkey sign-ins have a 93% success rate, compared with 63% for other methods. (FIDO Alliance Passkey Index, 2025)
- Passkeys reduce sign-in time by 73% — averaging 8.5 seconds versus 31.2 seconds. (FIDO Alliance, 2025)
- The FIDO Alliance measured a 30% conversion lift for passkey logins over passwords. (FIDO Alliance Passkey Index, 2025)
- Passkey adoption led to an 81% reduction in login-related help-desk incidents. (FIDO Alliance, 2025)
- More than a quarter (26%) of all sign-ins at surveyed organisations now use passkeys. (FIDO Alliance, 2025)
- Over a third (36%) of accounts at those organisations have a passkey enrolled. (FIDO Alliance, 2025)
- An average of 93% of accounts are now eligible for passkeys among FIDO member companies. (FIDO Alliance, 2025)
- 68% of organisations are deploying, piloting or rolling out passkeys for employee authentication. (FIDO Alliance, 2025)
- 85% of organisations that have adopted passkeys report strong satisfaction. (FIDO Alliance, 2025)
- 97% of organisations say they are willing to fully transition to passkey-based authentication, and 63% rank passkeys their top authentication investment priority. (FIDO Alliance, 2025)
- Nearly half of current implementers (49%) report passkey adoption rates above 75% among their users. (FIDO Alliance, 2025)
🔒 Not every account supports passkeys yet
Passkeys are spreading fast, but you still have dozens of logins that rely on passwords — and reused passwords are what attackers exploit. A password manager generates a unique, uncrackable password for every one of those accounts and stores your passkeys too, so you are covered on both sides of the transition.
Get NordPass →Affiliate link — we may earn a commission at no extra cost to you. See our disclosure.
Why the Password Is Being Replaced
Passkeys are winning because passwords keep failing. The figures below — from the Verizon DBIR, Microsoft, the FBI IC3, NordPass, Have I Been Pwned and LastPass — are the problem passkeys were built to solve.
- Stolen credentials were the initial access vector in 22% of breaches — the single most common entry point. (Verizon DBIR, 2025)
- 88% of basic web-application attacks involved the use of stolen credentials. (Verizon DBIR, 2025)
- Microsoft observes more than 7,000 password attacks per second — roughly 600 million a day. (Microsoft Digital Defense Report, 2025)
- 97% of identity attacks are password-spray attacks, trying common passwords against many accounts. (Microsoft, 2025)
- More than 99.9% of compromised accounts had no MFA enabled. (Microsoft, 2025)
- Internet crime caused $16.6 billion in reported losses in 2024 — a 33% jump over 2023. (FBI IC3, 2024)
- Phishing and spoofing were the most-reported crime, with 193,407 complaints. (FBI IC3, 2024)
- “123456” is again the world’s most common password, topping the list in six of the past seven years. (NordPass, 2025)
- 78% of the world’s most common passwords crack in under one second. (NordPass, 2025)
- Have I Been Pwned now indexes about 2 billion breached email addresses from aggregated credential leaks. (Have I Been Pwned, 2025)
- 91% of people know reusing passwords is insecure — yet do it anyway. (LastPass, Psychology of Passwords)
- 59% use the same or a similar password across multiple accounts. (LastPass)
- Even after cybersecurity education, only about 25% of people start using a password manager. (LastPass)
- Unlike a password, a passkey is never reused, guessed or typed, so it cannot be leaked in a breach or captured by a fake login page. (FIDO Alliance)
- Passkeys are phishing-resistant by design: no shared secret is ever transmitted, which defeats credential stuffing and phishing outright. (FIDO Alliance / NIST)
What Standards Bodies Say (NIST)
US federal guidance has moved decisively toward phishing-resistant, passwordless authentication. These points come from NIST Special Publication 800-63B and its supplements.
- NIST SP 800-63B-4 (Revision 4) requires that every verifier operating at Authentication Assurance Level 2 (AAL2) offer at least one phishing-resistant authentication option. (NIST, 2025)
- NIST’s 2024 supplement recognises “syncable authenticators” — FIDO passkeys — as phishing-resistant for both enterprise and public-facing use. (NIST, 2024)
- Revision 4 removed mandatory periodic password rotation, ending the “change your password every 90 days” rule. (NIST, 2025)
- Revision 4 dropped composition rules such as forced special characters and mixed case. (NIST, 2025)
- NIST instead recommends screening passwords against lists of known-breached credentials. (NIST, 2025)
- NIST endorses FIDO2 and WebAuthn — the open standards behind passkeys — as phishing-resistant authenticators. (NIST, 2025)
What These Numbers Mean
Read together, the 52 statistics tell one story: passwords are failing at scale and passkeys are the replacement the whole industry has aligned on. Stolen credentials still open 22% of breaches and 78% of common passwords crack in under a second, while passkeys deliver a 93% login success rate and cannot be phished or reused. Until every account you own supports passkeys, the safe bridge is a unique password on each login — generated by a password generator and stored in a manager. For the wider picture, see our companion roundups of password security statistics, two-factor authentication statistics and password attack statistics.
Frequently Asked Questions
How many people use passkeys in 2026?
According to the FIDO Alliance, more than 1 billion people have activated at least one passkey and over 15 billion online accounts now support them. Google reports over 800 million accounts using passkeys, and Amazon says more than 175 million of its customers sign in with passkeys.
Are passkeys actually more secure than passwords?
Yes. Passkeys are phishing-resistant by design: no shared secret is transmitted, so they cannot be leaked in a breach, reused, or captured by a fake login page. That matters because stolen credentials are the entry point in 22% of breaches (Verizon DBIR, 2025) and Microsoft records more than 7,000 password attacks per second.
Do passkeys work better than passwords in practice?
The data says clearly yes. The FIDO Alliance measured a 93% login success rate for passkeys versus 63% for traditional methods, a 73% reduction in sign-in time, and an 81% drop in login-related help-desk tickets. Microsoft reports a 98% passkey success rate compared with 32% for passwords.
Does NIST recommend passkeys?
Effectively yes. NIST SP 800-63B-4 requires AAL2 verifiers to offer at least one phishing-resistant option, and a 2024 supplement explicitly recognises syncable authenticators — FIDO passkeys — as phishing-resistant. Revision 4 also removed mandatory password rotation and complexity rules.
Should I still use a password manager if I have passkeys?
Yes. Passkey support is growing fast but is not yet universal, so you will keep dozens of password-based logins for years. A password manager generates a unique password for each of those accounts — eliminating reuse, the behaviour behind most credential-stuffing attacks — and modern managers store your passkeys too.
Methodology and Sources
Every statistic on this page is attributed inline to the organisation that published it, with the year of the source. Figures are quoted as reported by each primary source and were current as of July 2026. Primary sources:
- FIDO Alliance — Passkey Index and World Passkey Day 2025 data
- Google — Online Security Blog passkey disclosures, 2025
- Amazon — passwordless sign-in announcements, 2025
- Microsoft — Digital Defense Report 2025 and passkey-default announcement, May 2025
- Verizon — 2025 Data Breach Investigations Report (DBIR)
- FBI Internet Crime Complaint Center (IC3) — 2024 Internet Crime Report
- NordPass — Top 200 Most Common Passwords, 2025
- LastPass — Psychology of Passwords
- Have I Been Pwned — breached-credential index, 2025
- NIST — Special Publication 800-63B-4, Digital Identity Guidelines, and the 2024 syncable-authenticators supplement
- Straits Research — passwordless authentication market sizing, 2025
Note: where a statistic depends on a defined sample (for example, FIDO Passkey Index figures from surveyed enterprises), that context is stated with the figure. Percentages are reproduced as published and are not combined across differing denominators.