The apps the BSI singled out are the ones most often gated on a thumb: banking apps and password managers, opened with a fingerprint and nothing else. Its argument is that a fingerprint cannot be reissued the way a stolen password can, and its recommendation is to pair the biometric with a PIN or password rather than lean on it alone. Microsoft has been pushing consumer accounts in a related direction, moving personal accounts away from SMS codes toward passkeys.
Source: mobileidworld.com