Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
800,000 Passkeys in 10 WeeksFIDO & Passkeys
5 min readFor IAM Architects

800,000 Passkeys in 10 Weeks

The Challenge

GovTech faced a problem every IAM architect knows: how do you transition millions of users from phishable credentials when those credentials still work? By mid-2025, phishing had become Singapore's second most common scam, with victims losing S$39.9 million. The threat was real, persistent, and costly.

Singpass serves 5.5 million users across more than 1,400 government and private-sector services. This isn't a pilot program; it's critical national infrastructure involving healthcare records, tax filings, pension accounts, and banking. Any authentication change carries risks, but the phishing losses made inaction equally risky.

The core challenge: you can't force users to switch to FIDO2 passkeys overnight without disrupting access to essential services. Yet, gradual opt-in adoption often leads to low uptake. GovTech needed a strategy to drive adoption without causing support chaos or lockouts.

The Environment and Constraints

Singpass already supported multiple authentication methods: QR codes, SMS one-time passwords, and face verification. Adding passkeys introduced a fourth option into an ecosystem with established user habits, where backward compatibility with legacy services was crucial.

Technical constraints were significant. Desktop passkey support wouldn't arrive until the end of 2026, initially serving only mobile users. The platform fragmentation between iOS and Android required separate timelines. Any change to Singpass authentication affected government agencies like the Inland Revenue Authority of Singapore and CPF Board, plus private-sector partners including DBS Bank and Singtel.

GovTech committed to FIDO Alliance compliance, meaning device-bound cryptographic credentials with no reusable secrets transmitted during authentication. The benefit: interoperability with global services supporting FIDO passkeys. The constraint: no shortcuts on cryptographic requirements or proprietary extensions that break the standard.

The Approach Taken

GovTech launched passkeys for iPhone users on June 30 as a beta. The rollout was phased: users received in-app notifications prompting passkey creation, but the feature remained optional. Existing authentication methods continued to work.

By September 9, approximately 800,000 passkeys were registered. That's 10 weeks from beta launch to 800,000 enrolled credentials, representing roughly 14.5% of the 5.5 million total user base adopting the new method during the initial iOS-only phase.

The Android expansion followed the same pattern: phased notifications via the Singpass app, contingent on users updating to the latest version. No forced migration. No deprecation of SMS OTPs or QR codes. The passkey option sat alongside existing methods, reducing the risk of lockouts while creating a path for users to opt into phishing-resistant authentication.

The technical implementation followed FIDO2 specifications. Passkeys use public-key cryptography where the private key never leaves the user's device. During authentication, the device signs a challenge from the relying party using the private key. Because no password or OTP travels across the network, phishing sites can't intercept reusable credentials. The authentication fails if the origin doesn't match the registered domain.

Results and Metrics

The 800,000 passkeys registered in 10 weeks represent significant early adoption for a voluntary security upgrade. For context, that's faster uptake than most enterprise passkey pilots achieve, even with executive mandates.

The broader security impact shows up in the phishing numbers. Cases dropped from 3,772 in the first half of 2025 to 3,104 in the first half of 2026. Financial losses fell more sharply: from S$30 million to S$9.6 million over the same period. While not all reductions can be attributed to passkeys alone, the timing aligns with the authentication changes and awareness campaigns GovTech ran with partners like the Infocomm Media Development Authority.

The integration footprint remained stable. All 1,400+ services continued to accept Singpass authentication, meaning the passkey rollout didn't break existing relying party integrations or force service providers to rebuild their authentication flows.

What They Would Do Differently

GovTech hasn't published a retrospective, but the phased approach suggests lessons learned from earlier digital identity deployments. Keeping passkeys optional rather than mandatory shows an understanding that forced migration creates support load and user frustration.

The 18-month gap between mobile launch and planned desktop support (end-2026) is a real constraint. Desktop workers accessing government services still rely on phishable methods. Prioritizing platform-authenticator support for Windows Hello and Touch ID on macOS could close that gap faster, even if it means delaying feature parity on less-common desktop configurations.

Another area for improvement: credential recovery. FIDO2 passkeys eliminate password reset flows but introduce device-loss scenarios. If a user loses their phone and hasn't registered a backup passkey, they're locked out. The source article doesn't detail GovTech's account recovery process, but that's the operational challenge every passkey deployment eventually faces. You need fallback authentication that's still phishing-resistant but doesn't reintroduce the vulnerabilities you just eliminated.

Takeaways for Your Team

Start with voluntary adoption, not forced migration. GovTech's phased rollout let users opt into passkeys without breaking existing workflows. This approach reduces support tickets and gives you time to refine the user experience before broader promotion.

Plan for platform fragmentation. iOS and Android require separate implementation timelines. Desktop support adds another layer. If you're deploying passkeys across a diverse environment, map your user base by platform first and sequence your rollout to cover the largest populations early.

Don't deprecate legacy methods until adoption crosses 80%. Singpass kept SMS OTPs and QR codes active alongside passkeys. That's the right call. You can't enforce phishing-resistant authentication if 85% of your users haven't enrolled yet.

Measure the security outcome, not just enrollment. The drop in phishing losses from S$30 million to S$9.6 million matters more than the 800,000 registered passkeys. Track both the adoption curve and the incident reduction to justify continued investment.

Solve account recovery before you scale. Device loss is inevitable. Your FIDO2 deployment needs a recovery path that doesn't reintroduce phishable credentials. Consider backup passkeys on secondary devices or hardware security keys for high-risk accounts.

The Singpass expansion shows that phishing-resistant authentication can scale beyond enterprise pilots into national infrastructure. The 800,000 passkeys registered in 10 weeks prove that users will adopt better security when the friction is low and the value is clear. For IAM architects planning similar deployments, the lesson is straightforward: build for gradual adoption, maintain backward compatibility, and measure the security impact, not just the enrollment metrics.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like