AI-generated phishing messages prove more convincing than human-written scams
A new study from Brigham Young University found that AI-crafted phishing messages fooled recipients 28% of the time, compared to 21% for human-written ones. The AI matched or outperformed humans in prompting clicks in 80% of test cases, and participants could only correctly identify the message's source 52% of the time. The research highlights how personalized spear-phishing attacks, using details like co-worker names, are increasingly effective.
The Brigham Young University study tested AI-generated phishing against human-written scams, with AI fooling recipients 28% of the time versus 21% for humans. Participants correctly identified the message's source only 52% of the time, barely better than chance. Messages referencing co-workers proved 2.3 times more likely to generate clicks than those from generic organizations.
The research highlights how publicly available information—from LinkedIn profiles, company websites, and social media—can be rapidly compiled by AI into personalized spear-phishing messages. Job-related details made messages especially convincing. Since roughly 90% of corporate hacks originate from spear-phishing, the scalability of AI-generated deception represents a growing security concern.
This research could reshape how individuals and organizations approach email and text security. As AI-generated phishing becomes harder to distinguish from legitimate communication, people may become more vulnerable to scams that exploit personal details. Businesses could face increased risk of data breaches, potentially affecting employees, customers, and supply chains. The findings may also influence cybersecurity training, pushing toward verification habits rather than relying on stylistic detection. Society could see a shift toward more cautious digital communication, though the full extent of this impact remains uncertain.