Ahead of Black Hat 2026, Joel Witts, Content Director at Expert Insights, talks with Marc Olesen, CEO of Cofense, about how AI is reshaping the phishing threat landscape and what it takes to defend against it.
Olesen joined Cofense in January 2025, bringing over 30 years of technology leadership from roles including CEO at TokenEx, President and CEO at Sift, and senior leadership positions at Splunk and McAfee. He explains why polymorphic phishing, where AI generates a unique variation of an attack with every email, has become the default delivery model for attackers, and why AI has cut the time to build a phishing attack from 16 hours to five minutes.
In this episode, they discuss:
Why 88% of AI-generated phishing attacks are now unique, and what that means for signature and rules-based defenses
How business email compromise and OAuth/identity-based attacks still start with the inbox, even as phishing spreads to WhatsApp, Teams and other channels
Cofense’s post-perimeter approach: combining AI-driven detection with human-verified intelligence to neutralize reported threats in under 10 minutes
The “automation gap” between attacker and defender AI, and why a trained human layer will always be needed to close it
What the next 12 months of phishing could look like, from deepfakes and voice cloning to new email confirmation workflows
Olesen’s advice for security leaders building a defense-in-depth strategy against phishing








