Hackers Use Vercel v0 to Create Phishing Pages Using AI

2 July 2025 2 minutes Author: Newsman

Unknown cybercriminals have begun actively using the Vercel v0 generative tool to create believable phishing pages from text-only prompts. This demonstrates a new era in the use of AI for scalable attacks without the need for programming skills.

According to analysts at Okta Threat Intelligence, attackers are able to create functional fake login pages for well-known brands. In most cases, they do not just copy the design, but also place logos and other elements on the Vercel hosting itself – thereby increasing the credibility of the fake pages and avoiding detection.

The v0.dev platform allows anyone to create a site using only a text description. This means that even inexperienced attackers can generate phishing sites in a matter of minutes. With open repositories on GitHub cloning v0, this trend is only intensifying.

This case is part of a broader trend where LLMs (large language models) are being used for social engineering. Uncensored LLMs, such as WhiteRabbitNeo, are spreading in hacking circles, designed specifically for malicious purposes: writing malicious code, fake emails, deepfake videos, and other deception methods.

Cisco Talos notes that attackers are increasingly turning to such models because they have no restrictions – unlike secure commercial versions. This allows them to generate more dangerous and complex content.

The massive use of AI for phishing is not the future, but the present. Vercel v0, as an example, allows you to instantly create deception networks that are difficult to combat with traditional methods. Organizations need to reconsider their approaches to protection, implement monitoring of generative content, and train users to recognize new types of attacks. The next wave of phishing will not only be massive – it will be incredibly convincing.

Other related articles
News
Read more
Germany demands Google and Apple remove DeepSeek AI from marketplaces
Germany vs. DeepSeek AI - the conflict between GDPR and Chinese digital giants is gaining momentum. Will the app be removed from the App Store and Google Play? Learn all about DeepSeek AI, data protection in the EU, the Digital Services Act, and the risks of transferring information to China.
17
News
Read more
Canada bans Hikvision as a threat to national security
Canada has banned Hikvision, a Chinese video surveillance giant, over national security concerns. Find out why the government is urging citizens to get rid of cameras, how it relates to China's data transfer law, and why Hikvision is already banned in the US, Australia, and Europe.
29
News
Read more
Microsoft is removing password management from Authenticator
Microsoft is removing password support from Authenticator - starting in August 2025, users will lose access to saved data. Autofill will now work through Edge, and saved passwords must be transferred to other managers. What will change, how to export passwords, why Microsoft is switching to passkeys - learn everything about the Authenticator update and the passwordless future.
19
Found an error?
If you find an error, take a screenshot and send it to the bot.