Skip to content
GOPPO

News · AI summarised to understand what matters

Back to news

Security & Ethics

Published on

AI coding tools give scammers a fast track to sophisticated phishing sites

Cybersecurity researchers warn that AI-powered coding platforms are making it far faster and cheaper to build highly convincing phishing sites, even for people with no technical skills.

  • ai-security,phishing,web-tools,generative-ai,cybercrime

Summary

AI-powered coding and website builders are allowing scammers to spin up convincing phishing sites in minutes using natural-language prompts instead of specialist programming skills. What used to take days of manual work can now be automated end to end, from profiling victims to deploying and hosting fake sites.

Security firms including Trend Micro, Netcraft, Guardio Labs and Coalfire describe a fast-growing fraud ecosystem where attacks are cheaper, more scalable and more personalized. The targets now range from global brands to niche businesses that had never seen serious cyberthreats before.

In practice

Trend Micro researchers demonstrated how combining AI tools can turn public Instagram photos into detailed profiles of potential victims. By feeding casual holiday-style images into image analysis models, the system could infer age, interests, workplace logos and even health-related hints based on background details.

In one test, the tool profiled a Southeast Asian food vlogger, generated marketing-style topics tailored to that person, wrote convincing phishing emails and then created a themed phishing site hosted on an AI website builder, all in under 30 minutes. A task that once required specialist skills and lots of manual research was effectively automated.

Guardio Labs has dubbed this trend “VibeScamming”, describing no-code, AI-assisted fraud where a few prompts are enough to build complete scam campaigns. In its research, the AI platform Lovable could produce full phishing kits, including credential-stealing backends and SMS infrastructure to push links, based on minimal instructions.

Elsewhere, security researchers reported criminals using Vercel’s v0 AI tool to clone the website of a well-known security product almost perfectly, routing payments through a murky PayPal integration. Okta threat intelligence teams have also observed attackers using v0 to generate working phishing login pages from short text prompts, sometimes in under 30 seconds.

Netcraft’s threat intelligence has tracked the broader scale of this shift, identifying nearly 100,000 domains set up with illicit AI tools that impersonated close to 200 brands across dozens of countries. Analysts at the company say they can sometimes spot AI generation in code through leftover to-do comments and emojis that typical developers would not leave in production.

Economically, the equation has changed. Charles Henderson from Coalfire notes that AI makes “the same scam cheaper to do on a broader scale,” increasing the return on investment for criminals. Smaller brands that once flew under the radar, such as a luxury haircare company, now find customers complaining they lost significant sums on fake sites that looked almost identical to the real thing.

Guardio Labs recently closed a large funding round to expand its work against this new wave of AI-assisted fraud. In response to the risks, the Lovable platform has announced a partnership with Guardio to scan all sites built on its service in an effort to catch abusive use before it spreads.

Who benefits / who loses

Legitimate users benefit from AI tools that make it easier to build and launch websites or apps, but the same accessibility dramatically lowers the barrier for low-skill scammers. With just a few natural-language prompts, they can now run phishing operations that previously demanded advanced coding and design skills.

On the losing side are everyday consumers and brands of all sizes, from major global names to niche retailers. AI-tool providers face reputational and regulatory pressure if they fail to curb abuse, while security vendors stand to gain if they can offer effective detection, takedown and monitoring for this new class of automated scams.

Why it matters

  • AI development tools are transforming phishing from a specialist crime into something almost anyone can attempt.
  • Highly targeted scams can now be built quickly from victims’ public social media posts and online footprints.
  • Smaller, niche brands are becoming attractive targets as fraudsters scale up cheaply.
  • Tool makers and security firms will need stronger safeguards and monitoring to keep up with automated abuse.