
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Researchers have identified Bluekit, an AI-driven phishing kit that automates and enhances phishing attacks, including bypassing 2FA and mimicking over 40 brands. Reports show 86% of recent phishing campaigns now use AI, increasing the scale and effectiveness of credential theft and financial fraud globally.[AI generated]
Why's our monitor labelling this an incident or hazard?
Bluekit is an AI-enabled phishing platform that automates and enhances phishing attacks, including bypassing 2FA and mimicking many brands, which directly leads to harm such as credential theft and unauthorized access. The AI assistant helps craft convincing phishing emails, lowering barriers for attackers and increasing the risk and scale of harm. The event describes an active tool used for malicious purposes causing direct harm, fitting the definition of an AI Incident due to realized harm facilitated by AI systems.[AI generated]