Blog
Recent
Threat Intel

The Phish Bowl: AI, Identity, and Emerging Threats — Webinar recap & resource guide

LastPassPublishedJuly 16, 2026

This guide captures the key findings, threat intelligence, and live Q&A responses from the first-ever Phish Bowl Live: a webinar hosted by Stephanie Schneider and Mike Kosak from LastPass's Threat Intelligence Mitigations and Escalations (TIME) team. The session focused on the most urgent trends from LastPass's regional threat reports across APAC, Europe, and North America.

Read on to get a quick recap of the session and more insight into the questions asked and answered, including answers to the questions the team didn’t have time to address live. 

Key threats your team needs to understand

Trend 1: AI is fundamentally transforming the cyber threat landscape faster than most expect

The Five Eyes alliance (Australia, New Zealand, US, Canada, and the UK) issued a rare joint warning on the impact of AI on the cyber threat environment. The most concerning takeaway from the warning is that the timeline they cited was just months. That means we (individuals, businesses, and the collective security industry) don’t have the luxury of time to start preparing for and protecting ourselves against these AI-enabled threats.

AI is lowering the technical barrier for attackers across the board. What began with AI-polished phishing emails (eliminating the tell-tale grammar and spelling errors) has progressed into agentic, end-to-end autonomous attacks. The core change is that AI dramatically increases an attacker’s speed and scale. For instance, security researchers at Sysdig documented the first known autonomous LLM ransomware operation (JadePuffer) which could conduct reconnaissance, steal API credentials, move laterally, and adapt to failures in real time.

"Attackers adopt new technologies at the speed of compute. Defenders tend to adopt new technologies at the speed of committee." — Mike Kosak 

For defenders, AI is also creating new tools (AI SOC solutions, agentic detection capabilities), but bureaucratic and compliance overhead means adoption lags. The window to shore up security fundamentals is closing.

Trend 2: The most common attack pattern is also the most basic

Across every region in the LastPass threat reports, the most prevalent attack pattern was an attacker using a stolen username and password to simply log in. No dramatic breach. No keyboard-furiously-typing movie moment. Just someone walking through the front door with a valid key.

The FortiGate attack illustrates the scale where approximately 430,000 internet-facing FortiGate firewalls and VPNs were targeted globally. Attackers used stolen credentials or brute-force/password-spraying to gain access, then planted credential sniffers inside those devices, leading to the discovery of over 110 million harvested credentials. The threat actor was linked to the Inc and Lynx ransomware families.

Notably, a disproportionate share of impacted victims were small to mid-sized businesses (SMBs) with 200 or fewer employees. SMBs remain attractive targets for attackers, who often perceive them as having less mature security programs and fewer resources dedicated to cybersecurity.

The infostealer pipeline

Much of this credential theft flows through infostealer malware. This is software running silently on endpoint devices that harvests everything stored in a browser: saved passwords, session tokens, cookies. Some key facts include:

  • Last year alone, infostealers exposed approximately 1.8 billion credentials and sold billions more session cookies.

  • Infostealers increasingly target session tokens, not just passwords, allowing attackers to authenticate without triggering MFA prompts.

  • Credentials stolen years ago are still being used. If that password was never changed, it's still valid.

  • Even with active antivirus, over 50% of infostealer infections go undetected (SpyCloud data).

"We've also seen infostealers grabbing session tokens now. It's not just credentials — because it's a lot easier to validate active sessions without a password or an MFA prompt."— Stephanie Schneider

Trend 3: Attackers exploit the tools your employees already trust.

The tools employees use every day, like AI assistants, collaboration platforms, open-source libraries, are increasingly the entry point. Not because those tools are inherently insecure, but because attackers exploit the trust those tools carry.

Two examples from recent weeks:

  • Microsoft Teams phishing: Attackers impersonating IT support on Teams, routing malicious command-and-control traffic through the Teams infrastructure itself — making it look like legitimate traffic to a firewall. Microsoft has documented protections, but social engineering pressure drives people past them.

  • Prompt injection via GitHub + Claude: NOMA Security disclosed a vulnerability where a threat actor could post a public pull request on an organization's GitHub page, worded as a prompt injection, that would extract sensitive data from the private repository and publish it publicly. Patched responsibly, but illustrative of a growing class of threat.

“As organizations integrate AI into development workflows, least-privilege access principles apply more urgently than ever. Know what access your AI integrations have — and limit it.” — Mike Kosak

Action items to take back to your team

  • Unique, complex credentials for every account. Use a password manager. Credential stuffing only works when passwords are reused.

  • Enable MFA wherever available. It raises the bar, even if token theft can circumvent it in some cases.

  • Patch consistently. Combined with credential hygiene, this covers ~80% of exposure for most organizations (reference: Australia's Essential Eight).

  • Monitor the dark web. Your credentials may already be posted. Without monitoring, you won't know until after an attack.

  • Verify unexpected IT requests out-of-band. If someone on Teams, WhatsApp, or email asks you to download something or reset credentials, call IT directly on a known number before acting.

  • Review AI integrations with a least-privilege lens. Understand what data access your AI tools have and constrain it. Reference: Google's Secure AI Framework (saif.google.com).

Audience poll: What AI is really doing to the threat landscape

During the live session, attendees voted on which topic they wanted to explore more deeply. The winner by a clear majority was: "What AI is actually doing to the threat landscape."


Here is a full summary of what Stephanie and Mike covered in that deep dive:

It's a force multiplier, not a new category of threat

The core message from Mike and Stephanie: AI isn't inventing new attacks from scratch. The threats (credential theft, ransomware, phishing, social engineering) are the same ones that organizations have faced for years. What AI changes is the speed, scale, and accessibility of those attacks.

The analogy used on the call: what used to require sophisticated technical skills can now be executed by anyone with basic technical literacy. And for those already skilled, AI compresses what previously took days or weeks into hours or minutes.

"It's really that speed and scale aspect of it. At its core, it's the same threats we've seen for a long time. While it sounds scary — and it is — it does open the technological barrier of entry so anybody with basic technical literacy can jump in." — Mike Kosak

What AI-enabled attacks actually look like today

Phishing: the quality gap has closed

The earliest visible sign of AI in the threat landscape was in phishing emails. The traditional tells, such as awkward grammar, misspellings, odd phrasing, began disappearing as threat actors started using AI to draft their lures. That shift is now complete. Assume any phishing email you receive has been AI-polished.

Agentic ransomware: JadePuffer

The JadePuffer operation, documented by Sysdig, is the first publicly known autonomous LLM-driven ransomware attack. What made it notable was not the attack type, as ransomware is not new, but how it operated:

It exploited a known CVE autonomously, without human direction at each step.

  • It conducted reconnaissance, stole API credentials for AI services and cloud platforms, and moved laterally through the environment.

  • It recovered and adapted from failures in real time, pivoting its approach on its own.

  • It self-narrated its actions, describing to itself what it was doing so the LLM could plan the next step.

That last point is actually a defensive opportunity. Because the agent was generating plain-language descriptions of its actions in traffic, defenders can write detections that look for that kind of natural language in network communication. This is a signal that wouldn't exist in a traditional attack.

Deepfakes and voice cloning in social engineering

AI-generated deepfakes (both video and audio) are increasingly being used in social engineering attacks. Today, they're getting better, but giveaways still exist. On video, you might notice an ear disappearing, an extra finger, or unnatural lag in response time. On voice calls, there can be delays and flat intonation.

The concern isn't that deepfakes are perfect today. It's that they're improving faster than most people's ability to spot them, and they're already convincing enough to fool targets who aren't specifically looking for them. Attacks documented include CEO impersonation (directing employees to transfer funds or purchase gift cards) and targeted attacks on elderly individuals.

“The question to ask isn't ‘could I tell this is a deepfake?’ it's ‘do I have a process that doesn't require me to make that judgment call?’ Verification protocols that go out-of-band protect you regardless of how convincing the fake is.” — Mike Kosak

Malicious LLMs purpose-built for attacks

Beyond using mainstream AI tools, threat actors are now creating and distributing malicious LLMs specifically designed to guide attacks. This tactic effectively creates a 'how to hack' assistant with no safety guardrails. This further lowers the barrier to entry by making attack planning accessible to anyone, not just those with technical knowledge.

What defenders can do right now

  • Don't wait for perfect AI defenses. The fundamentals, including credential hygiene, patching, security training, still protect against the majority of AI-amplified attacks because the attack vectors haven't fundamentally changed.

  • Build out-of-band verification into your culture. Deepfakes and voice cloning defeat verification processes that rely on voice or video alone. A call-back protocol to a known number breaks the chain regardless of how convincing the impersonation is.

  • Watch for plain-language signals in network traffic. Agentic attacks like JadePuffer generate natural language in their communication streams, a detection surface that traditional attacks don't create.

  • Use AI to fight AI. AI SOC tools, behavioral analytics, and agentic detection capabilities are available now. Prioritize evaluating and deploying them. Don’t wait for the full committee approval cycle.

  • Vet your AI tools carefully. Stick to known, established models. Supply chain attacks targeting open-source AI libraries and cheap or free extensions are a growing vector, and some have turned out to be malicious.

"Now it's more important to avoid reusing the same password over and over again, which opens you up to credential stuffing attacks.". — Stephanie Schneider

Questions from the session

Here are the questions asked during the webinar and the answers from our team. Some were answered live, and some we ran out of time for in the live session, so have provided follow up answers for here. 

Q1 What steps would you recommend for newer or smaller businesses who want to stay ahead of cybersecurity threats? Would smaller/newer businesses be more at risk with advancing AI?

Yes, smaller businesses are disproportionately targeted. The FortiGate attack data showed a heavy concentration of victims at companies with 200 or fewer employees. Ransomware attacks across our reports from each region also reflect this trend. The good news is that the protections that work aren't expensive or exotic. Mike's guidance included focusing on the basics: password protection, consistent patching, and security education. That combination covers approximately 80% of your exposure. Australia's Essential Eight is a practical framework worth referencing regardless of your location. Unique, complex credentials and MFA are the starting points.

Q2 Any updates and features coming from LastPass?

Our product team has a few exciting things on the roadmap this year, stay tuned for more updates! For organizations looking for enhanced security controls, visibility, and administrative insights, LastPass Business Max offers additional capabilities beyond our standard business offering. Contact our sales team for more information. 

Q3 Are infostealers installed on firewalls, PCs, or browsers?

Infostealers are installed on devices themselves, typically your computer. Once on the device, they target whatever credentials or session tokens are accessible, with browsers being the primary target. Most infostealers immediately look in browser files for stored credentials, extract them, and also grab any active session tokens. That's why storing credentials in your browser is specifically advised against; it's the first place these tools look.

Q4 What tools are best for dark web monitoring, as many are offering it?

Dark web monitoring is a critical capability. Credentials from infostealer infections often surface on dark web marketplaces, sometimes months or years after the initial theft. LastPass includes dark web monitoring as part of its services, and most password managers generally tend to include it. 

Q5 Best ways to prevent phishing attempts via email? Are alias emails a good solution?

Alias email addresses can help, but they are not one of the best defenses against phishing by themselves. For email-specific defenses, use phishing-resistant MFA, implement strong email security controls, and be cautious of suspicious emails, especially when they involve a sense of urgency. AI has made phishing emails far more convincing by eliminating the grammar and spelling errors that were traditionally the tell. Teams-based phishing and social engineering tactics are on the rise, so verifying unexpected requests through a trusted, out-of-band channel is important.

Q6 Given many infostealers self-delete after harvesting, is there any best practice for detecting/protecting against them?

For proactive measures, avoid clicking unknown links or downloading cracked software or game cheats (a common infostealer delivery vector), and be wary of "ClickFix" social engineering that tricks users into running installers themselves. Reactively: even though antivirus catches roughly 50% of infections, there is a meaningful gap. Dark web monitoring fills this gap by alerting you when your credentials surface, giving you a chance to rotate them before an attacker uses them. Using unique passwords for each account also limits blast radius: if one credential is stolen, only that account is at risk.

Q7 Help me understand the difference between passwords and tokens?

A password is what you type in to prove your identity. It's a string of characters that the system validates. A session token is what the system assigns you after successful authentication: a unique identifier proving you've already been verified, so you don't have to re-enter your password with every interaction. The risk: if an attacker steals a session token before it expires, they can authenticate as you without ever knowing your password, and without triggering an MFA prompt. This is why infostealers now specifically target session cookies alongside stored passwords.

Q8 Are security defenses advancing fast enough to stay up with malicious AI advances? It seems like defenses could fall behind, much like policy changes drag behind.

The honest answer is that defenders do lag. Attackers can adopt AI at the speed of compute. Defenders, especially in larger organizations, must navigate software approvals, GRC review, and procurement cycles. That gap is real and concerning. That said, AI defensive tools are emerging with tools and developments like AI SOC platforms and agentic detection capabilities. The practical recommendation is to identify the highest-leverage AI applications for your security stack and move on those quickly, while also ensuring the fundamentals that still work remain in place. AI amplifies threats, but the same credential hygiene and patching practices that have always mattered continue to be the highest-return defense.

In the words of Stephanie Schneider, “Stay safe out there. Don’t take the bait.”

Stay tuned for the next edition of The Phish Bowl live, coming in October 2026. In the meantime, stay ahead of emerging threats and automatically discover every SaaS app across your org with LastPass. Talk to our team or start a free trial.

 
Share this post via:share on linkedinshare on xshare on facebooksend an email