Researchers at Okta Threat Intelligence have revealed that unknown cybercriminals are leveraging v0 (a Generative AI tool from Vercel) to create fake login pages that closely mimic authentic websites.

According to analysts Houssem Eddine Bordjiba and Paula De la Hoz, this is a significant development in the use of generative AI by malicious actors, who are now able to create fully functional phishing websites simply by entering text prompts in natural language.
The v0 enables users to produce basic landing pages and full-stack apps, without requiring programming knowledge.
See also: Hackers use AI to attack small and medium-sized businesses
Okta has identified cases where fraudsters have used the platform to create realistic replicas of popular brand login pages. After being notified of the abuse of v0, Vercel took immediate action, cutting off access to the malicious sites.
At the same time, use of Vercel's infrastructure was detected to host alleged corporate logos and other resources (most likely, the hackers were trying to exploit the platform's credibility to avoid detection).
Unlike traditional phishing kits that require technical training, tools like v0 allow for the mass production of phishing pages quickly and easily – with a simple command. This means that even inexperienced cybercriminals can now launch phishing campaigns with a high level of persuasiveness and at a much lower cost.
See also: Asana says MCP AI feature exposed customer data
Cybercriminals are leveraging GenAI for phishing attacks
Recent activity confirms a worrying trend: Threat actors are actively experimenting with leading GenAI tools, aiming to enhance the effectiveness and reach of phishing campaigns.
As Okta Threat Intelligence experts point out , the use of tools like Vercel 's v0.dev allows new cybercriminals to easily and quickly create high-quality phishing pages .
Recently, it has been observed that more and more attackers are turning to large language models (LLM) for criminal activities, creating uncensored versions of these models that are explicitly designed for illegal purposes. One such LLM that has gained popularity in the cybercrime landscape is WhiteRabbitNeo, which is advertised as an “Uncensored AI model for (Dev) SecOps teams.”

The use of AI for phishing activities is no longer limited to simple fake emails. Tactics such as the use of cloned voices, deepfake videos , and automated social engineering scripts are on the rise, making the deception not only more convincing, but also more massive.
See also: Hackers advertise new Nytheon AI tool on hacking forum
The defense needs to change level
Traditional protection (antivirus, spam filters, awareness training) is no longer sufficient. We need:
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- AI that detects AI-generated scams
- Zero Trust architecture
- Enhanced identity verification
- Regulatory framework for responsible GenAI development
The threat is not theoretical. It is here, it is already operational, and it is expanding rapidly. Without a coordinated response — from technology companies, governments, and security organizations — we risk seeing an explosion of phishing, fraud, and espionage that will undermine trust in the digital ecosystem.
Source: thehackernews.com
