Phishing Attacks Just Got a Whole Lot Harder to Stop
The cat-and-mouse game between cybersecurity professionals and attackers has just taken a significant turn in favor of the latter. Artificial intelligence (AI) has revolutionized the way phishing campaigns are designed, executed, and dismantled, making it increasingly difficult for blocklists and indicator-based detection methods to keep up.
For years, cybersecurity teams have relied on blocklists to identify and prevent phishing attacks. However, this approach is no longer effective in today’s fast-paced digital landscape. Phishing domains are now only active for an average of fewer than two days, with a staggering 89% of them disappearing within 15 days or less. By the time a domain makes it onto a blocklist, the campaign has already moved on to new infrastructure, rendering the list useless.
The problem is not just that phishing infrastructure rotates quickly. Modern attacks are designed to be disposable from the outset, with attackers proactively tearing down pages and spinning up new ones to stay ahead of detection. This approach is made possible by AI-powered tools that can generate convincing phishing pages in minutes, complete with unique codebases that evade static analysis.
The use of trusted hosting platforms, such as Cloudflare Workers and Microsoft Dynamics, has also become widespread among attackers. These platforms are often combined with bot protection, screening checks, and complex redirect chains to filter out researchers and automated scanners. As a result, 95% of in-browser attacks detected by Push Security now use some form of bot protection.
The cost of creating phishing pages has also been reduced significantly thanks to AI-powered tools that can vibe-code entire sites from a screenshot of a legitimate login page. This approach allows attackers to create convincing frontends with unique codebases that are difficult to detect.
Furthermore, phishing delivery is increasingly relying on legitimate services, such as AI chatbot sharing features and search ad placement, to inherit the domain reputation of platforms no blocklist would ever flag. This has created an environment where adding indicators to a blocklist is akin to playing whac-a-mole in a game that’s rigged against you from the start.
In light of these developments, cybersecurity teams must rethink their approach to detecting and preventing phishing attacks. Relying solely on indicator-based detection methods will no longer suffice. Instead, they need to adopt more proactive measures, such as analyzing network traffic patterns and user behavior to identify potential threats before they occur.
Source: Bleeping Computer — 2026-08-05