Just a small clarification, attackers can definitely steal a passkey from your key store and use it if your corporate settings are incorrect IE. device attestation is turned off.
My company has already responded to multiple breaches where this has been what quickly follows an initial intrusion.