Vibe-Coded Phishing Kits: What Okta's Threat Chief Says Lock Down Now
Attackers build custom phishing kits in days using AI. Okta's Jeremy Kirk explains stolen sessions, AI-assisted attacks, and why passkeys are non-negotiable.
Attackers are now shipping custom phishing kits roughly once a week using vibe-coding techniques, making sophisticated credential theft accessible to low-skill criminals. If you run a small business, your biggest immediate risk is stolen session tokens, not just stolen passwords. Okta's director of threat intelligence, Jeremy Kirk, told iTWire at Oktane 2026 that passkeys are the one control with no exceptions, because they are the only credential type that cannot be phished or replayed from a stolen session.
Why should a small business care about AI-assisted phishing kits?
Because the barrier to entry just collapsed. Attackers no longer need a development team or deep technical skills to build a convincing, targeted phishing kit. According to Okta's director of threat intelligence, Jeremy Kirk, speaking at Oktane 2026 in Las Vegas, threat actors are now vibe-coding custom phishing kits at a pace of roughly one new kit per week. That cadence used to take months and a capable developer. Now it takes a few prompts and a free AI tool.
This matters to SMB operators specifically because enterprise security teams have threat intelligence feeds, dedicated analysts, and tooling budgets. You probably don't. Which means you're facing a more capable attacker with a thinner defense.
What exactly is a vibe-coded phishing kit?
Vibe coding means using AI to generate functional code by describing what you want in plain language, without writing the underlying logic yourself. Applied to attacks, a criminal can describe a phishing page that mimics a specific SaaS login, handles MFA prompts, and logs credentials, then have a working kit in hours. Kirk's point is that this is no longer theoretical. It is happening weekly in the wild.
The kits are also getting smarter about what they steal. Passwords alone are less valuable than they used to be, because most business tools now require a second factor. So attackers have shifted focus to session tokens, the cookies your browser holds after a successful login that prove you already authenticated.
What is session token theft and why is it worse than a stolen password?
When you log into a tool like Google Workspace or Microsoft 365, the platform issues a session token that keeps you logged in without re-entering credentials. If an attacker steals that token, they can impersonate your session entirely, bypassing the password and the MFA step that already happened.
This technique, sometimes called session hijacking or a pass-the-cookie attack, is not new. What is new is the industrial scale. Stolen AI sessions are now being traded on criminal markets according to Kirk's Oktane 2026 briefing. That includes sessions for tools like ChatGPT, Claude, and other AI platforms your team may be using for sensitive work.
"Stolen AI sessions are being actively traded. An attacker with your ChatGPT session can see everything you've been working on."
For an SMB, a stolen AI session could expose client data, internal strategy, financial information, or anything else your team has fed into those tools. The data never left through the front door. The attacker just walked in through your open browser.
What controls actually stop these attacks?
Kirk's answer on passkeys was unambiguous: no exceptions. Here is why that framing matters.
Most SMB security advice is hedged. Use MFA where you can. Enable SSO if the budget allows. Passkeys are different because they are architecturally phish-proof. A passkey is a cryptographic key pair tied to a specific domain. A phishing site cannot harvest a passkey the way it harvests a password or an OTP code, because the key only responds to the legitimate origin domain. There is nothing for a fake login page to intercept.
The practical controls worth prioritizing, based on what Kirk outlined:
- Passkeys over passwords everywhere they are supported. Google, Microsoft, GitHub, and most major SaaS platforms now support them. There is no reason to delay.
- Session lifetime limits. Configure your SaaS tools to expire sessions after a reasonable idle period. Shorter session windows shrink the window an attacker has to use a stolen token.
- Conditional access or device trust. Tools like Okta, Microsoft Entra, and even Google Workspace Business tiers let you require that a login comes from a managed or recognized device. A stolen token from an unrecognized device gets blocked.
- Audit AI tool access. If your team uses ChatGPT, Claude, Gemini, or similar tools, treat those sessions like you treat access to your CRM. Know who is logged in, on what devices, and what data they are feeding in.
How are attackers using AI on their end, beyond building phishing kits?
The attack surface has expanded in two directions. Attackers use AI to build better kits faster, as covered above. They also use it to process stolen data more efficiently. A credential dump that used to require manual sorting can now be run through an AI-assisted script that identifies high-value accounts, matches credentials to known SaaS tools, and prioritizes targets automatically.
Kirk also noted that AI lowers the language and writing barrier. Phishing emails used to fail on grammar and awkward phrasing. AI-generated lures read cleanly and can be personalized at scale using scraped LinkedIn data or company websites. An SMB with 12 employees is not too small to be targeted this way. The kit does not care about company size.
Does multi-factor authentication still matter if session tokens can be stolen?
Yes, but the type of MFA matters enormously. SMS codes and authenticator app OTPs can be intercepted in real time by an attacker running a reverse proxy phishing kit. The user types in their OTP, the kit forwards it to the real site, and the attacker gets a valid session. This is called an adversary-in-the-middle (AiTM) attack and it is one of the most common patterns Kirk's team tracks.
Passkeys and hardware security keys (FIDO2) are the only MFA types that are AiTM-resistant by design. Everything else buys time. Those two actually close the door.
| MFA Type | Phish-Resistant | Blocks AiTM | SMB Cost | |---|---|---|---| | SMS one-time code | No | No | Free | | Authenticator app OTP | No | No | Free | | Push notification | No | Partial | Free-low | | Passkey (device-based) | Yes | Yes | Free | | Hardware key (FIDO2) | Yes | Yes | $25-$60/key |
What we'd actually do
- Audit your MFA types this week. List every tool your team accesses and check whether it supports passkeys. Migrate the highest-risk accounts (email, finance, CRM, cloud storage) first. Do not wait for a full rollout plan before moving the critical ones.
- Set session expiration policies on your top three SaaS tools. Most admins have never touched the default session lifetime settings. Log into your admin console for Google Workspace, Microsoft 365, or whatever your core platform is and shorten idle session windows. One hour of idle timeout is a reasonable starting point.
- Brief your team on AI session risk specifically. Most employees understand not to click phishing links. Very few understand that their ChatGPT or Claude session, if stolen, hands an attacker everything they have ever typed into it. A 10-minute team conversation about logging out of AI tools on shared or personal devices, and not pasting sensitive client data into consumer AI tools, costs nothing and closes a real gap.
If you want to work through identity security, AI governance, or team training with operators who are actually running this for clients, that is what we do at skool.com/aiforbusiness.
FAQ
What is a vibe-coded phishing kit?
A phishing kit built using AI code generation tools, where the attacker describes what they want in plain language and the AI produces working code. It requires minimal technical skill and can be completed in hours. Okta's threat intelligence director reported these are being produced at roughly one new kit per week.
Can stolen session tokens bypass MFA?
Yes. A session token is issued after authentication, including MFA, is already complete. If an attacker steals that token, they skip the login process entirely. This is why session lifetime limits and phish-resistant credentials like passkeys matter more than adding another MFA layer on top of a vulnerable one.
Are passkeys actually ready for small business use?
Yes. Google Workspace, Microsoft 365, GitHub, Shopify, and most major SaaS platforms support passkeys today. Setup takes minutes per account. They are free, built into modern devices, and are the only credential type that is architecturally resistant to phishing and adversary-in-the-middle attacks. There is no good reason to delay on high-risk accounts.
Want this running in your business?
The Skool community is where we show the full builds, share the templates, and help you implement. Three tiers, from team training to fractional AI expert.
- Weekly Q&A with Alex and Cameron
- Templates and frameworks you can steal
- Real builds, running in real businesses
More on Governance
49% of UK Small Firms Had a Cyber Incident. Fix the Basics First.
Half of UK small firms suffered a cyber incident last year. ESET's 2026 report shows it wasn't AI attacks causing damage, it was basic security gaps SMBs can close today.
Fake HR Apps Are Stealing Payroll Access From SMBs
Hackers built AI-powered fake clones of US HR and payroll platforms to trick staff into downloading remote access tools. Here is how to spot and block it.
AI Agents Are Opening New Doors Into Your Business Data
AI agents expand your attack surface while making phishing and ransomware cheaper to run. Here's what SMBs need to do right now to stay protected.