In a rapidly evolving threat landscape where cybercriminals leverage the latest technological advances, Brett Winterford, Vice President of Okta Threat Intelligence, shared his perspectives on the weaponisation of AI in phishing attacks during a recent EITN interview. Brett ’s insights highlight how AI is not only increasing the scale and sophistication of phishing campaigns, but fundamentally altering the rules of engagement for defenders and attackers alike.
A new era in phishing velocity and sophistication
“AI tools are providing threat actors an ability to build phishing infrastructure and customise the delivery of lures at a previously unobserved speed and scale,” Brett explained. Phishing-as-a-Service (PhaaS) platforms had already reduced the time it took for even less-skilled adversaries to set up attacks from hours to minutes, but with generative AI, “now we’re observing these tools build it in seconds.”

The result? A dramatic uptick not just in the velocity and volume of phishing campaigns, but also their sophistication. According to AI-Powered Phishing: A Paradigm Shift in Cyber Threats, phishing kits and infrastructure constructed using AI closely mimic real-world sign-in experiences, reflecting the branding, language and workflow specific to each target. “The phishing lures will often more accurately mimic the daily sign-in experience or the targeted user. They are more customised—right down to the language, branding and workflow of the target,” he noted.
An exploding threat landscape and novel AI tools
Asked about trends and statistics, Brett described a “surge” in both the number and diversity of threat actors. “The number of threat actors we are actively tracking has exploded in recent months, as has the diversity of phishing kits and services available to them.” These advancements aren’t limited to infrastructure. Attackers are deploying generative language models, deepfakes, and AI-driven chatbots as part of their toolkit.
Of particular concern is usage by state-aligned actors. “We have observed state-aligned actors using a broad variety of generative AI tools to develop and manage fraudulent personas, develop compelling job applications, perform mock interviews with AI agents, assist during live interviews and to perform contracted work,” Brett explained.
Defensive strategies: A focus on identity
The nature of these threats demands a shift in defensive postures. Traditional security controls such as email and web filtering, or relying solely on user vigilance, are increasingly insufficient. Brett warned, “We shouldn’t put users in a position where they have to make a call on whether a site is legitimate, because AI is able to make all parts of a phishing site (apart from the top-level domain) look the same as the legitimate sign-in page.”
He recommended cryptographically binding a user’s authentication method to the legitimate site—technology Okta delivers with FastPass. But, as he admits, “We have a long journey ahead to convince all customers to shift to phishing-resistant authentication.”
Looking forward: Evolution and defence
Winterford anticipated that attackers may not need to innovate much further in coming years: “The rate of growth in AI-enabled phishing tools is already outstripping the rate of growth in passwordless, phishing-resistant authentication.” He expects adversaries will target user enrolment and recovery flows, where deepfake and generative tools can be used to compromise even strong identity systems.
Industry response and leadership advice
Industry-wide standards, like those pursued in the IPSIE (Interoperability Profile for Secure Identity in the Enterprise) working group, of which Okta is a founding member, are crucial steps. “If all apps were IPSIE-compliant, we’d put a huge dent in the attack surface for phishing,” Brett said.
For business leaders and CISOs preparing for this new era, Brett shared a quote from a cybersecurity leader at HubSpot:
“Run, don’t walk, to phishing-resistant authentication.”
As AI continues to revolutionise both defences and attacks, the need for strong, adaptive, and standardised security practices has never been more pressing.









