When Phishing Sites Only Show Up for the Victim
Most fraud detection assumes a scam will show itself when a scanner loads the page. Attackers figured that out early, and many impersonation sites now decide whether to render based on who is visiting. A fake Blocket login might only appear for a Swedish mobile IP, on a Swedish-language browser, arriving from the right referrer. Everyone else gets a parked page or a challenge screen.
Join Bolster AI and Vend, the company behind FINN, Blocket, DBA, Bilbasen, Tori, and Oikotie, for a candid conversation about a detection gap that undermines the whole category. Vend’s marketplaces connect millions of people with strangers every day, which makes them a prime target for this kind of attack.
What You’ll Learn
- What Vend was hearing from users that its tooling wasn’t surfacing
- Why cloaking became standard practice once generative AI made convincing fake sites nearly free
- How location, device, language, and referrer checks let a live phishing site look like nothing to automated scanners
- What it took to capture these pages under the same conditions a real victim meets
Why Watch?
If you protect a brand with a defined home market, this is the gap you’re most likely measuring as zero. A site that is live and stealing credentials but looks blank to your scanner shows up in your reporting as no threat at all. This session covers where that blind spot comes from and what it looks like from the inside.
Want to Go Deeper?
Read the latest company and product updates, security research, market trends, industry thought leadership, and more from Bolster’s AI security resources.