Skip to content
Putting technology to work.
Insights to guide decisions and action.

Search articles

Before the CEO's Account Gets Taken Over — Two-Step Verification and Passkey Migration for SMEs

Table of contents · 7 items

"Apparently, a business partner's account was compromised, and a suspicious email came to us under that company's name asking us to change the bank account for invoice payments. We were almost tricked. It suddenly terrified me that the same thing could happen to us." Recently, an executive from a company with about 30 employees shared this concern with us. Account hijacking is not someone else's problem; it connects directly to financial loss and brand reputation damage through business partners. That realization hit home.

Account hijacking is not an issue exclusive to large enterprises. In fact, SMEs are targeted precisely because their defenses tend to be lighter. Password reuse, increasingly sophisticated phishing, and the complacency of believing "we won't be targeted"—when these factors coincide, accounts belonging to presidents or accounting personnel are compromised, leading to fraudulent emails sent to business partners and corporate data breaches. In this article, we outline how SMEs should strengthen authentication by transitioning to phishing-resistant passkeys without locking out employees, from the perspective of an ongoing custom development partner.

Why SME accounts are targeted

First, let us understand why SMEs are targeted so frequently. The reason is simple: defenses are sparse.

At many SMEs, business account passwords are reused across multiple external services. Lists of passwords leaked from any single platform circulate on the dark web, and attackers use them to attempt automated credential stuffing across numerous targets. When passwords are reused, a single breach becomes a gateway into all corporate accounts.

Another factor is the increasing sophistication of phishing. Deceptive emails that look identical to official communications—claiming "Your password is about to expire" or "Suspicious login detected"—lure users to fake login pages to harvest credentials. In recent years, AI has made phishing text natural and convincing, making it far harder to spot. We covered protecting yourself against incoming malicious emails in our article on AI phishing defense, but no matter how vigilant people are, there is a limit to how reliably humans can detect spoofed sites. That is why organizations need an authentication architecture where accounts cannot be hijacked even if a password is stolen.

SMS and code-based two-step verification are no longer foolproof

For those who assume "we're safe because we turned on two-step verification," this distinction is critical to understand. Two-step verification encompasses different methods, and their resilience against phishing varies substantially.

Authentication methodPhishing resistanceWeakness
SMS and email codesLowCan be entered into fake sites and exploited in real time
Authenticator app codesModerateCan likewise be stolen via fake sites
Passkeys and security keysHighIncompatible with fake sites by fundamental design

Entering codes sent via SMS or email, or inputting numeric tokens from an authenticator app, is certainly safer than relying on passwords alone. However, they fall short against sophisticated phishing. If a victim enters both their password and one-time code into a spoofed site set up by an attacker, the attacker can relay those credentials in real time to the legitimate service and log in. As long as the mechanism relies on typing in a code, this loophole cannot be closed.

In contrast, passkeys and hardware security keys are inherently immune to phishing by architectural design. With a passkey, user presence is verified via fingerprint, facial recognition, or screen lock, while the device cryptographically verifies whether the site being accessed is genuine. Authentication simply fails to execute against a fraudulent domain. Because there is no code to type in, there is nothing for attackers to steal. Google positions passkeys as the most phishing-resistant authentication method available. While the technical shift toward passwordless authentication is detailed in our article on passkey migration, the main takeaway is that future security upgrades are shifting from code-based authentication toward passkeys.

Google is already moving toward mandatory enforcement

This shift is being accelerated by platform providers. Google has been progressively mandating the activation of two-step verification for Google Workspace administrator accounts. Because administrator compromises inflict the most catastrophic damage, mandatory enforcement has begun there first.

This is an important signal for SMEs. We are transitioning from an era where two-step verification was recommended to one where services cannot be used without it. Rather than being forced into compliance reactively, proactively taking steps to strengthen authentication across all employees creates far less operational friction. In particular, high-privilege administrator accounts, finance accounts handling money transfers, and executive accounts directly tied to corporate credibility should be migrated promptly to phishing-resistant methods like passkeys and security keys. Combining strong authentication with entry-point restrictions—such as permitting logins only from authorized devices and conditions—creates multi-layered defense. We explore this methodology in our article on context-aware access.

Forcing passkeys on all employees overnight leads to lockouts

This is the most common pitfall encountered in custom development and client support, so it warrants emphasis upfront: deciding that "since passkeys resist phishing, let's make them mandatory for all employees tomorrow" will almost certainly lock employees out of their accounts.

Passkeys are tied to physical devices. When employees upgrade smartphones, switch laptops, or experience lost or broken devices, they cannot access their accounts without pre-configured recovery workflows. If you enforce passkeys across the entire company without defining backup authentication methods, employees upgrading their phones will find themselves locked out one after another, burying administrators under emergency support requests.

The proper rollout sequence begins with high-impact accounts—such as administrators and executives—paired with secondary recovery mechanisms, like backup security keys or backup codes. After testing workflows with a small cohort and validating recovery procedures for lost devices and upgrades, you can gradually expand the scope to all staff. Strengthening security should follow the rule of preparing the path to recovery before migrating individuals, rather than handing out unmanaged heavy locks all at once.

Case study: A company that migrated after an attempted takeover of their accounting account

Let us look at a real-world example. A company with about 40 employees (name withheld) reached out after an incident: "Our accountant received a spoofed login alert email that looked completely genuine, and came within inches of entering their password and verification code. We noticed right before hitting submit, but we cannot count on being so lucky next time." The company had already instituted SMS-based two-step verification, but anxiety that it could not prevent attacks via credential-harvesting phishing sites prompted their consultation.

Instead of rolling out changes company-wide immediately, we proceeded in order of potential damage. First, we switched logins for several high-risk accounts—executives, accounting, and administrators—to passkeys and security keys. Simultaneously, each person was provisioned with a secondary backup key, and recovery steps for lost or damaged devices were formally documented. After operating with this core team for about a month and successfully staging a device upgrade test to verify smooth recovery, we expanded rollout to all employees. We explained to staff that passkeys make logging in faster and easier via biometric checks while completely preventing phishing, ensuring buy-in before migration.

As a result, eliminating manual code entry rendered this class of phishing attacks architecturally impossible. Furthermore, zero lockout incidents occurred during device upgrades because recovery procedures had been established beforehand. The most effective move was not imposing aggressive security on everyone at once: it was starting with the highest-risk accounts and preparing recovery paths before widening the scope. Following the proper sequence raised the baseline of defense without locking out a single employee.

First, identify the three accounts that would cause the most damage if hijacked

Before selecting software tools to strengthen authentication, clarify one thing: identify the three accounts in your company that would cause the greatest damage if compromised. In most cases, these are the CEO, accounting, and administrator accounts. Migrate these three to phishing-resistant passkeys or security keys first, and pair them with backup recovery methods. Doing just this closes the most dangerous attack vectors beforehand.

Account hijacking represents an imminent risk for SMEs with light defenses, directly triggering financial losses and reputational damage involving business partners. Code-based two-step verification is no longer foolproof, and authentication standards are shifting toward passkeys. However, forcing them on everyone overnight will trigger employee lockouts. Start with the highest-risk accounts, prepare recovery options, and migrate staff step-by-step. Handled in the right order, authentication upgrades provide exceptionally cost-effective protection for small and medium-sized businesses.

If you are unsettled after witnessing a business partner's account breach, want to verify whether your current two-step verification is adequate, or want to transition to passkeys without locking out your team, please feel free to reach out through GleamHub's free IT and Google Workspace consultations. From auditing critical accounts to staged passkey and security key rollouts and establishing lost-device recovery procedures, we will partner with you to solidify your defenses safely.

Sources

Share this articleXFacebook
Kakeru Suzuki

Fascinated by the possibilities of technology, has had a deep interest in programming and digital art since student days

Turn this article's theme into your company's next step

Concrete steps forward for your organization.

We organize your desired architecture, legacy systems, and operational requirements to formulate your next steps toward execution.

  • Desired architecture
  • Integration with existing environments
  • Operational requirements
Consult on development & operations initiatives

You can consult with us from the initial conceptual stage. Details from this article will be carried over to the inquiry form.

Receive the latest articles by email