The dangerous part is not the passkey itself, but the human workflow around identity recovery, where urgency and trust can be turned into account takeover.
A guilty plea tied to a large cloud theft case shows how a single criminal operation can create outsized privacy and legal risk, even when the technical entry point remains unconfirmed.
A leak-site entry naming “G*” and alleging stolen, compressed Salesforce data is unverified, yet it points straight at the controls that decide how SaaS data leaves the building.