Good add, you're right that the click was only the entry point, the real failure was that nothing flagged one account suddenly pulling thousands of documents. If I had to pick one control for a mid-size club today, I'd lean toward alerts on bulk document access over passkeys alone. Passkeys stop THIS specific attack (credential phishing), but they don't stop an already-authenticated account from being used to exfiltrate data, whether that's through a compromised session, an insider, or malware on the device. Anomaly detection on access patterns catches a wider range of ways this could go wrong, not just phishing. Ideally you'd want both, but if budget forces a choice, I'd protect the data movement, not just the login.
Great reframing: the verdict everyone is arguing about traces back to one link that "looked like Tuesday". The detail I would add is that the click was only step one; the bigger failure was that one official's session could reach thousands of internal documents without anything flagging the bulk access. Phishing-resistant MFA like passkeys would have blunted the click, but access logging would have caught the exfiltration. If you had to pick one control for a mid-size club today, would it be passkeys or alerts on bulk document access?
iin1005h1428