
Fraudology Podcast with Karisse Hendrick 5-Minute Phishing: How AI is Revolutionizing Scams and Morphing Attacks
Mar 3, 2026
Matt Vega, Chief Fraud Strategist at Sardine and veteran fraud investigator in fintech and crypto. He explains how AI can build pixel-perfect phishing sites in minutes and steal 2FA codes. They cover polymorphic AI agents that adapt to defenses and tactics like dust trailing. The conversation highlights detection tools like hidden watermarks, beacon tech, and why basic card-to-name and behavioral checks still matter.
AI Snips
Chapters
Transcript
Episode notes
Phishing Can Hijack 2FA To Create Trusted Devices
- Phishing sites can execute man-in-the-middle flows to capture 2FA and convert attacker devices into trusted devices.
- Vega described forwarding credentials to the real bank, prompting victims for OTPs, then using that OTP to gain fully authenticated access and establish a trusted device.
Proactively Monitor Domains And Buy Variations
- Maintain continuous threat intelligence: monitor WHOIS, watch for similar domain registrations, and proactively buy similar domains.
- Vega advises buying all plausible domain permutations and automating takedowns via whois lookups to reduce attacker choices.
Brands Using AI Content Complicate Takedowns
- Many brands now use AI-generated marketing content which creates legal gray areas for takedowns.
- Vega noted companies use AI images on sites, complicating copyright-based takedowns versus traditional cloned-photo claims.

