Sophisticated attacks no longer require sophisticated attackers
AI models allow any attacker to use capabilities that were accessible before only to nation state-level groups.
Anthropic Threat Intelligence, Sep ‘26Fight back AI-enabled phishing
directly from the login
AI is amplifying the capabilities of attackers and the scale of phishing attacks, making organizations of every size a target.
AI models allow any attacker to use capabilities that were accessible before only to nation state-level groups.
Anthropic Threat Intelligence, Sep ‘26EvilTokens PhaaS attack targeted 12,000 accounts across 10,000 organizations, each with a custom AI-generated email lure, personalized to the targeted user.
Microsoft Threat Intelligence, Sep ‘26Almost all modern phishing kits offer AI-enabled user device spoofing and risk analysis bot detection to bypass defensive mechanisms.
ANY.RUN H1 2026 Cyber Risk ReportThe first AI-powered phishing counterattack that kills AitM / MitM directly in the login page. Added to your IdP admin portal in less than 30 minutes – fully transparent to the user.
Relock Witness is the first AI-powered countermeasure that terminates the AitM / MitM phishing attacks, with 100% deterministic precision.
At each user authentication the Witness server injects a challenge directly into the login flow. This counterattack inevitably reveals any malicious phishing kit sitting between the user and the legitimate page and kills the connection.
The user sees nothing. If they click on a phishing link, their login attempt on the fake page will be terminated before they introduce their password or any other credentials.
Attacker's response - fingerprint declaration
Attacker's response - challenge execution

Witness generates a unique challenge that can only be correctly executed by the device attempting to log in.Even an attacker that can modify the entire information flow between the page and the user is forced to either fail or reveal the presence of the malicious phishing kit.

A proprietary AI model that uses offensive methods against attacks to prevent bypass. Witness is always evolving and changing live, so any reconnaissance is useless to mount an attack.

Our red team lab keeps the model behind the challenge up to speed on the latest threat developments and our own security research into the frontier of AI-enabled phishing.

Built to be used by IAM admins, directly with major Identity Providers such as Okta, Auth0, or PingID. No application or infra changes required. No user education needed.