Good add, you're right that the click was only the entry point, the real failure was that nothing flagged one account suddenly pulling thousands of documents. If I had to pick one control for a mid-size club today, I'd lean toward alerts on bulk document access over passkeys alone. Passkeys stop THIS specific attack (credential phishing), but they don't stop an already-authenticated account from being used to exfiltrate data, whether that's through a compromised session, an insider, or malware on the device. Anomaly detection on access patterns catches a wider range of ways this could go wrong, not just phishing. Ideally you'd want both, but if budget forces a choice, I'd protect the data movement, not just the login.
